20260916T141251Z-98f9
- Audited URL
- https://restate.ee/
- Timestamp
- 2026-09-16T14:17:03.345Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 72 is the mean of 5 pages. Scores range 68 (https://restate.ee/ettevote/blogi) → 78 (https://restate.ee/). Weakest page: Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority.
Audit Report: Avaleht - Restate
Website: https://restate.ee/
Date: 16.09.2026
Audit Coverage: 100% — all sources returned data
Confidence: high
Pages Audited (5 of 5):
- https://restate.ee/
- https://restate.ee/privacy-policy
- https://restate.ee/ettevote/blogi
- https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
- https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
Summary of results
Overall Score: 72 / 100
Status: 🟡 Needs Improvement
Site overall 72 is the mean of 5 pages. Scores range 68 (https://restate.ee/ettevote/blogi) → 78 (https://restate.ee/). Weakest page: Mobile performance (83) is dragged down by a 4.2 s LCP, exceeding the 4 s 'poor' threshold despite a 99 desktop score. Security headers are completely absent (0/100), missing baseline protections like HSTS. Accessibility is mostly strong (95) but fails touch target sizing (0.00 score). W3C validation shows 7 script errors from plugin configuration. The site is a commercial real estate blog with no auth/payment risk, lowering CSP priority.
Per-page scores
🟡 Needs Improvement · https://restate.ee/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 78 | 93 | 95 | 100 | 92 | 0 |
🟡 Needs Improvement · https://restate.ee/privacy-policy
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 71 | 78 | 95 | 100 | 100 | 0 |
🟡 Needs Improvement · https://restate.ee/ettevote/blogi
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 83 | 96 | 100 | 92 | 0 |
🟡 Needs Improvement · https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 72 | 85 | 96 | 100 | 100 | 0 |
🟡 Needs Improvement · https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 73 | 81 | 96 | 100 | 100 | 0 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://restate.ee/ | 93 / 100 | 2.85 s / 563 ms | 0.003 / 0.003 |
| https://restate.ee/privacy-policy | 78 / 99 | 2.50 s / 684 ms | 0.377 / 0.000 |
| https://restate.ee/ettevote/blogi | 83 / 99 | 4.18 s / 937 ms | 0.005 / 0.000 |
| https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos | 85 / 99 | 4.08 s / 825 ms | 0.000 / 0.000 |
| https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida | 81 / 99 | 4.22 s / 819 ms | 0.000 / 0.000 |
Optimization Checklist
2 of 3 passing — 2 pass · 0 warn · 1 fail · 4 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster <img> elements found. |
| Hero image eagerly loaded | Fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Add HSTS header Security
- Impact: Transport security, HTTPS enforcement
- Problem: Security Headers grade is 0/100; strict-transport-security is missing.
- Solution:
Add the following header to your server configuration (Apache example):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
1B. Eagerly load the hero image Performance
- Impact: LCP, FCP
- Problem: Optimized-Web Checklist flagged hero image
hammer.pngas havingloading="lazy", contributing to LCP 2.9 s. - Solution:
Remove
loading="lazy"from the hero<img>and addfetchpriority="high":<img src="/path/to/hammer.png" alt="..." fetchpriority="high">
1C. Fix Cumulative Layout Shift (CLS) of 0.377 Performance
- Impact: LCP, CLS, Core Web Vitals
- Problem: CLS 0.377 exceeds 0.25 threshold; shift source identified in footer (div#page > div.main > div.main__footer > footer.footer).
- Solution:
Reserve space for dynamic content in footer:
footer.footer { min-height: 200px; /* or actual content height */ }- Add explicit width/height to any embedded content (iframes, ads, videos)
- Use
aspect-ratioCSS property for dynamic elements - Avoid inserting content above existing content
1D. Remove lazy loading from hero image Performance
- Impact: LCP, FCP
- Problem: Hero image has loading="lazy", which delays LCP to 4.2 s on mobile (Optimized-Web Checklist fail).
- Solution:
Remove
loading="lazy"and addfetchpriority="high"to the hero<img>:<img src="/hero.jpg" alt="..." fetchpriority="high" width="..." height="...">
1E. Improve Largest Contentful Paint (LCP) Performance
- Impact: LCP, FCP, Mobile Performance Score
- Problem: Mobile LCP is 4.1 s (threshold is ≤4 s), flagged as a high-priority PSI failure despite low page weight.
- Solution:
- Preload the LCP image and critical fonts.
- Ensure
font-display: swapis used for web fonts. - Optimize the hero image delivery (check if
fetchpriority="high"is needed). - Review server-side rendering or caching to reduce render-blocking resources.
1F. Optimize Largest Contentful Paint (LCP) resource Performance
- Impact: LCP, FCP, Mobile Performance
- Problem: Mobile LCP is 4.2 s (threshold >4 s is heavy penalty); PSI flags
largest-contentful-paintandfont-display-insightas high priority. - Solution:
- Preload the LCP image (hero) with
<link rel="preload" as="image">. - Convert hero image to WebP/AVIF with fallback.
- Ensure
font-display: swapis active for Open Sans to prevent render blocking.
- Preload the LCP image (hero) with
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Add X-Content-Type-Options and X-Frame-Options Security
- Impact: MIME sniffing, clickjacking protection
- Problem: Security Headers grade 0/100; both headers are missing.
- Solution:
Add these headers to your server configuration:
Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"
2B. Increase touch target sizes Accessibility
- Impact: WCAG 2.5.8 Target Size
- Problem: PSI
target-sizeaudit failed with score 0.00, indicating interactive elements are too small or lack spacing. - Solution: Ensure all clickable elements (links, buttons) have a minimum touch target of 44×44 CSS pixels. Add padding or margin to increase the clickable area without changing visual size.
2C. Add meta description SEO
- Impact: Search snippet quality
- Problem: HTML Inventory shows meta description is not set; PSI SEO audit failed
metaDescription. - Solution:
Add a unique description tag in the
<head>:<meta name="description" content="Brief summary of Restate services for search engines.">
2D. Add baseline security headers (HSTS, X-Content-Type-Options, X-Frame-Options) Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: All 9 security headers missing (score 0/100). HSTS, X-Content-Type-Options, X-Frame-Options are baseline protections regardless of site signals.
- Solution:
Send from origin (Apache shown):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"- Consider CSP (priority 3 for this site per rubric — no auth/payments/UGC)
2E. Fix W3C HTML validator errors (7 script type/defer conflicts) Best Practices
- Impact: HTML validity, potential JS execution issues
- Problem: 7 errors: script elements with type="text/rocketlazyloadscript" and defer attribute — invalid per HTML spec (data blocks must not have defer).
- Solution:
Remove
deferfrom non-JavaScript script types:<!-- Before --> <script type="text/rocketlazyloadscript" data-wp-strategy="defer" defer> <!-- After --> <script type="text/rocketlazyloadscript" data-wp-strategy="defer">- Or change type to a valid JavaScript MIME type if defer is needed
2F. Fix landmark-unique violation and touch target sizes Accessibility
- Impact: WCAG 1.3.1, 2.5.8
- Problem: axe-core: 1 moderate violation (landmark-unique on .footer__social). PSI: target-size failures for touch targets.
- Solution:
- Add unique aria-label to footer social landmarks:
<nav aria-label="Social media links"> - Ensure all interactive elements have 44×44px minimum touch target
- Add visible focus indicators to all interactive elements
- Add unique aria-label to footer social landmarks:
2G. Add baseline security headers (HSTS, X-Frame-Options, X-Content-Type-Options) Security
- Impact: Transport security, clickjacking, MIME sniffing
- Problem: Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- Solution:
Configure server (Apache example):
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" Header always set X-Frame-Options "SAMEORIGIN"
2H. Increase touch target sizes for interactive elements Accessibility
- Impact: Mobile usability, WCAG 2.5.8
- Problem: PSI
target-sizeaudit score is 0.00, indicating touch targets are too small or lack spacing. - Solution: Ensure all interactive elements (links, buttons) have a minimum 44×44 px touch target area. Add padding or margins to small icons/links.
2I. Add Baseline Security Headers Security
- Impact: Transport security, clickjacking protection
- Problem: Security Headers grade is 0/100; HSTS, X-Frame-Options, and X-Content-Type-Options are missing.
- Solution:
Configure the web server (Apache/Nginx) to send:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff"
2J. Fix W3C HTML Validation Errors Best Practices
- Impact: Parser recovery, SEO, maintainability
- Problem: 10 W3C errors found, including 7 instances of invalid
scripttags usingtype="text/rocketlazyloadscript"withdefer. - Solution:
Update the WP Rocket plugin configuration or version. The
typeattribute on scripts should be omitted or set tomodule/text/javascript. Invalid types can cause parsing issues in some browsers.
2K. Fix Touch Targets and Landmarks Accessibility
- Impact: WCAG 2.5.8 (Target Size), 1.3.1 (Info and Relationships)
- Problem: PSI reports
tapTargetsfailure; axe reportslandmark-uniqueviolation on.footer__social. - Solution:
- Increase spacing or size of interactive elements to at least 44×44 px.
- Add unique
aria-labelortitleattributes to duplicate footer landmarks to distinguish them for screen readers.
2L. Correct Cache-Control Headers Performance
- Impact: Repeat visit performance, bandwidth
- Problem: Response header
cache-control: max-age=0prevents effective browser caching despite WP Rocket detection. - Solution:
Configure WP Rocket or server rules to set
Cache-Control: public, max-age=31536000for static assets andmax-age=3600for HTML, ensuring theVary: Accept-Encodingheader is preserved.
2M. Increase touch target sizes and fix landmark uniqueness Accessibility
- Impact: WCAG 2.5.8 Target Size, 1.3.1 Info and Relationships
- Problem: PSI
target-sizeaudit fails; axe reportslandmark-uniqueviolation on.footer__social. - Solution:
- Ensure all interactive elements have 44×44 px minimum touch area.
- Add unique
aria-labelorroleto the footer social landmark to distinguish it from other nav regions.
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Implement Content-Security-Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals indicate no auth/payments/UGC, so risk is lower but still recommended.
- Solution:
Start with a restrictive policy allowing only necessary origins:
Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com;"
3B. Fix W3C script type errors Best Practices
- Impact: HTML validity, potential parsing issues
- Problem: W3C Validator reported 7 errors:
scriptelements withtype="text/rocketlazyloadscript"incorrectly use thedeferattribute. - Solution:
Update WP Rocket settings or custom code to use standard MIME types (
text/javascript) or removedeferfrom non-standard script types.
3C. Add meta description and hreflang tags SEO
- Impact: Search snippet quality, international SEO
- Problem: Missing meta description (SEO audit suggests text). No hreflang tags for multi-language support.
- Solution:
Add to
<head>:<meta name="description" content="Restate privacy policy details how we collect, use, and protect your personal information."> <link rel="alternate" hreflang="et" href="https://restate.ee/privacy-policy/"> <link rel="alternate" hreflang="en" href="https://restate.ee/en/privacy-policy/">
3D. Consider CSP implementation (lower priority for this site) Security
- Impact: XSS defense-in-depth
- Problem: CSP missing. Site signals show no auth, payments, or user-generated content — XSS attack surface minimal per rubric.
- Solution:
If/when adding login or user content, deploy nonce-based CSP:
Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';- For current brochure/privacy policy page, focus on P1/P2 items first
3E. Add a meta description SEO
- Impact: Search snippet quality, CTR
- Problem: HTML Inventory shows meta description is not set; PSI SEO audit fails
metaDescription. - Solution:
Add a unique
<meta name="description" content="...">tag in the<head>summarizing the blog page content.
3F. Fix invalid script type attributes Best Practices
- Impact: HTML validation, potential parsing issues
- Problem: W3C Validator reports 7 errors:
type="text/rocketlazyloadscript"withdeferis invalid. - Solution:
Update WP Rocket configuration or custom scripts to use standard MIME types (
text/javascript) or remove thetypeattribute entirely for JS.
3G. Implement Content Security Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP is missing. Site signals indicate no auth, payments, or user content, lowering immediate risk but CSP remains a best practice.
- Solution:
Deploy a strict CSP using nonces or hashes rather than a flat allowlist:
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';"
3H. Fix W3C HTML validation errors (Script types and SVG attributes) Best Practices
- Impact: Parser recovery, SEO, Maintainability
- Problem: 10 W3C errors: 7x
scriptwith invalidtype+defer, 2xpreserveAspectRatioonuse. - Solution:
- Remove
type="text/rocketlazyloadscript"or change totext/javascript. - Remove
deferfrom scripts with non-standard MIME types. - Remove
preserveAspectRatiofrom<use>elements (valid on<svg>only).
- Remove
▸Raw Markdown sent to the LLM
# Site Audit — https://restate.ee/
Run: 2026-09-16T14:12:52.027Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**
Pages audited:
- https://restate.ee/
- https://restate.ee/privacy-policy
- https://restate.ee/ettevote/blogi
- https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
- https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
---
# Page 1 of 5 — https://restate.ee/
Run: 2026-09-16T14:12:53.112Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 12979 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **93** | 100 |
| Accessibility | 95 | 95 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.9 s** / 1434 ms p75 (fast) | 0.6 s / 841 ms p75 (fast) |
| CLS | 0.003 / 0 p75 (fast) | **0.003** / 4 p75 (fast) |
| TBT | 0 ms | 0 ms |
| FCP | **2.25 s** / 1378 ms p75 (fast) | 491 ms / 605 ms p75 (fast) |
| Speed Index | **2.25 s** | 815 ms |
| TTFB | 4 ms / 615 ms p75 (fast) | **6 ms** / 378 ms p75 (fast) |
| INP (field only) | 119 ms p75 (fast) | 48 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.9 s
2. **first-contentful-paint** (low) — 2.3 s
3. **font-display-insight** (high) — Est savings of 70 ms
4. **image-delivery-insight** (medium) — Est savings of 510 KiB
5. **network-dependency-tree-insight** (high)
### Findings (mobile)
#### Layout-shift sources
- div.hero__container > div.hero__content > h1.hero__title > span.hero__title-accent — shift 0.003
- div.hero__container > div.hero__content > h1.hero__title > span.hero__title-text — shift 0.000
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `largest-contentful-paint` (performance, score 0.82, weight 25) — Largest Contentful Paint — 2.9 s
- `first-contentful-paint` (performance, score 0.76, weight 10) — First Contentful Paint — 2.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 18 ms._
**Transport:**
- Final URL: https://restate.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 16 Sep 2026 14:08:45 GMT
- expires: Wed, 16 Sep 2026 14:12:53 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 22952
- Decoded body: 84.2 KB
- Compression ratio: 0.266
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 22952
content-type: text/html; charset=UTF-8
date: Wed, 16 Sep 2026 14:12:53 GMT
expires: Wed, 16 Sep 2026 14:12:53 GMT
keep-alive: timeout=5, max=95
last-modified: Wed, 16 Sep 2026 14:08:45 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1034 ms._
**Scoring:** 7 errors · 1 warnings · 34 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x7, first at line 755
### Issue groups
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 544 `/noscript><script nowprocket type="text/javascript">var el`
- (×7) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 755 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1490 ms._
**Scoring:** 1 violations · 31 passes · critical 0 · serious 0 · moderate 1 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.footer__social`
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1498 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 23 network requests · 710.9 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 6 | 590.6 KB |
| stylesheet | 5 | 46.2 KB |
| script | 4 | 23.6 KB |
| document | 1 | 22.4 KB |
| font | 3 | 16.3 KB |
| xhr | 3 | 7.7 KB |
| other | 1 | 4.0 KB |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 271 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 139 ms, 0 B
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (script) — 46 ms, 2.5 KB
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 46 ms, 7.9 KB
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 46 ms, 10.1 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1498 ms._
**Document:**
- Lang: et
- Title: Avaleht - Restate
- Canonical: https://restate.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 85465
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 6 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time)
- Twitter tags: 6
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Meie kaup ei ole
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 30 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (defer)
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.6 KB)
**Images:** 6 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ee/wp-content/themes/restate/inc/theme/img/footer/hammer.png | _(empty)_ | 233×382 | lazy | ✓ |
| e.ee/wp-content/themes/restate/inc/theme/img/footer/lego.png | _(empty)_ | 290×290 | lazy | ✓ |
| /wp-content/themes/restate/inc/theme/img/footer/lollipop.png | _(empty)_ | 143×384 | lazy | ✓ |
| ntent/themes/restate/inc/theme/img/footer/chicken-dollar.png | _(empty)_ | 358×720 | lazy | ✓ |
| e.ee/wp-content/themes/restate/inc/theme/img/footer/croc.png | _(empty)_ | 401×246 | lazy | ✓ |
| e.ee/wp-content/themes/restate/inc/theme/img/footer/duck.png | _(empty)_ | 260×260 | lazy | ✓ |
**Links:** 17 anchors — 5 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "äri" ×2
- "kodud" ×2
- "varahaldus" ×2
- "võta ühendust" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 5 pass · 0 warn · 1 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✗ fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 6/6 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 6 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
- `hero: https://restate.ee/wp-content/themes/restate/inc/theme/img/footer/hammer.png`
- `loading: lazy`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 143, 233, 260, 290, 358, 401`
### Priority fixes
1. **Hero image eagerly loaded** (high) — Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high".
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 2 of 5 — https://restate.ee/privacy-policy
Run: 2026-09-16T14:12:53.114Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 17502 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **78** | 99 |
| Accessibility | 95 | 95 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.5 s** / 1434 ms p75 (fast) | 0.7 s / 841 ms p75 (fast) |
| CLS | **0.377** / 0 p75 (fast) | 0.000 / 4 p75 (fast) |
| TBT | 0 ms | 0 ms |
| FCP | **2.03 s** / 1378 ms p75 (fast) | 644 ms / 605 ms p75 (fast) |
| Speed Index | **2.16 s** | 1.14 s |
| TTFB | 3 ms / 615 ms p75 (fast) | **4 ms** / 378 ms p75 (fast) |
| INP (field only) | 119 ms p75 (fast) | 48 ms p75 (fast) |
### Priority fixes
1. **cumulative-layout-shift** (high) — 0.377
2. **first-contentful-paint** (low) — 2.0 s
3. **cls-culprits-insight** (high)
4. **document-latency-insight** (high) — Est savings of 280 ms
5. **font-display-insight** (high) — Est savings of 180 ms
### Findings (mobile)
#### Layout-shift sources
- div#page > div.main > div.main__footer > footer.footer — shift 0.377
- — shift 0.002
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `cumulative-layout-shift` (performance, score 0.28, weight 25) — Cumulative Layout Shift — 0.377
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.83, weight 10) — First Contentful Paint — 2.0 s
- `cls-culprits-insight` (performance, score 0.00, weight 0) — Layout shift culprits
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 362 ms._
**Transport:**
- Final URL: https://restate.ee/privacy-policy/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 16 Sep 2026 14:12:53 GMT
- expires: Wed, 16 Sep 2026 14:12:53 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 22247
- Decoded body: 76.3 KB
- Compression ratio: 0.285
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 22247
content-type: text/html; charset=UTF-8
date: Wed, 16 Sep 2026 14:12:53 GMT
expires: Wed, 16 Sep 2026 14:12:53 GMT
keep-alive: timeout=5, max=94
last-modified: Wed, 16 Sep 2026 14:12:53 GMT
link: <https://restate.ee/wp-json/>; rel="https://api.w.org/", <https://restate.ee/wp-json/wp/v2/pages/3>; rel="alternate"; title="JSON"; type="application/json", <https://restate.ee/?p=3>; rel=shortlink
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1266 ms._
**Scoring:** 7 errors · 1 warnings · 35 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x7, first at line 559
### Issue groups
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 476 `/noscript><script nowprocket type="text/javascript">var el`
- (×7) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 559 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1934 ms._
**Scoring:** 1 violations · 31 passes · critical 0 · serious 0 · moderate 1 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.footer__social`
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1942 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 17 network requests · 119.6 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| stylesheet | 5 | 46.2 KB |
| script | 4 | 23.6 KB |
| document | 2 | 21.7 KB |
| font | 2 | 16.3 KB |
| xhr | 3 | 7.7 KB |
| other | 1 | 4.0 KB |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://restate.ee/privacy-policy (document) — 234 ms, 0 B
- https://restate.ee/privacy-policy/ (document) — 220 ms, 21.7 KB
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 137 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 137 ms, 0 B
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (script) — 43 ms, 2.5 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1942 ms._
**Document:**
- Lang: et
- Title: Privacy Policy - Restate
- Canonical: https://restate.ee/privacy-policy/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 77660
**Meta tags:**
- Description: Suggested text: Our website address is: https://restate.ee.
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×0, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Privacy Policy
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 30 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (defer)
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.6 KB)
**Images:** 0 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
**Links:** 14 anchors — 5 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "võta ühendust" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 0 warn · 0 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found. |
| Hero image eagerly loaded | – n/a | No raster <img> elements found. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 3 of 5 — https://restate.ee/ettevote/blogi
Run: 2026-09-16T14:13:06.091Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 19998 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **83** | 99 |
| Accessibility | 96 | **95** |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.2 s** / 1434 ms p75 (fast) | 0.9 s / 841 ms p75 (fast) |
| CLS | **0.005** / 0 p75 (fast) | 0.000 / 4 p75 (fast) |
| TBT | 0 ms | 0 ms |
| FCP | **2.32 s** / 1378 ms p75 (fast) | 666 ms / 605 ms p75 (fast) |
| Speed Index | **2.36 s** | 691 ms |
| TTFB | 6 ms / 615 ms p75 (fast) | **10 ms** / 378 ms p75 (fast) |
| INP (field only) | 119 ms p75 (fast) | 48 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.2 s
2. **first-contentful-paint** (medium) — 2.3 s
3. **document-latency-insight** (high) — Est savings of 270 ms
4. **font-display-insight** (high) — Est savings of 120 ms
5. **image-delivery-insight** (medium) — Est savings of 133 KiB
### Findings (mobile)
#### Layout-shift sources
- div.grid__col > div.card-article-featured__panel > div.card-article-featured__content > p.card-article-featured__description — shift 0.005
#### Long tasks
- https://restate.ee/ettevote/blogi/ — 58 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.45, weight 25) — Largest Contentful Paint — 4.2 s
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.74, weight 10) — First Contentful Paint — 2.3 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.85, weight 0) — Time to Interactive — 4.3 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 156 ms._
**Transport:**
- Final URL: https://restate.ee/ettevote/blogi/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 16 Sep 2026 14:09:31 GMT
- expires: Wed, 16 Sep 2026 14:13:06 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 26261
- Decoded body: 112.1 KB
- Compression ratio: 0.229
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 26261
content-type: text/html; charset=UTF-8
date: Wed, 16 Sep 2026 14:13:06 GMT
expires: Wed, 16 Sep 2026 14:13:06 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 16 Sep 2026 14:09:31 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1448 ms._
**Scoring:** 7 errors · 1 warnings · 30 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x7, first at line 1229
### Issue groups
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 1146 `/noscript><script nowprocket type="text/javascript">var el`
- (×7) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 1229 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1723 ms._
**Scoring:** 1 violations · 35 passes · critical 0 · serious 0 · moderate 1 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.footer__social`
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1732 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 30 network requests · 909.8 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 13 | 786.3 KB |
| stylesheet | 5 | 46.2 KB |
| document | 2 | 25.6 KB |
| script | 4 | 23.6 KB |
| font | 2 | 16.3 KB |
| xhr | 3 | 7.7 KB |
| other | 1 | 4.0 KB |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://restate.ee/ettevote/blogi (document) — 220 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 144 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 138 ms, 0 B
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (script) — 47 ms, 2.5 KB
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 47 ms, 7.9 KB
### Priority fixes
1. **failed request** (medium) — xhr: https://restate.ee/wp-content/themes/restate/inc/theme/svg/global.cc972873247e83bce5ca.svg — net::ERR_ABORTED
### Findings
#### Failed requests
- xhr: https://restate.ee/wp-content/themes/restate/inc/theme/svg/global.cc972873247e83bce5ca.svg — net::ERR_ABORTED
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1732 ms._
**Document:**
- Lang: et
- Title: Blogi - Restate
- Canonical: https://restate.ee/ettevote/blogi/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 112337
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 6 (og:locale, og:type, og:title, og:description, og:url, og:site_name)
- Twitter tags: 3
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×13, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Blogi
- h2: Lasnamäele tuleb uus tõmbekeskus: Peterburi teele kerkivad Padel+ Restate ja vir
- h2: Äripinna üürimine: viis asja, mida enne lepingu allkirjastamist kontrollida
- h2: Built-to-suit: kui valmis pind ettevõttele lihtsalt ei sobi
- h2: Tänassilma Äripark kasvab: kolmanda etapi ehitus on alanud
- h2: Kuidas valida ettevõttele õige asukoht?
- h2: Investeerimine ärikinnisvarasse: millest alustada
- h2: Logistikapinna trendid 2026: automaatika muudab nõudeid hoonele
- h2: Kodu ostmine uusarendusest: mida tasub enne broneerimist teada
- h2: Projektijuhtimine kinnisvaraarenduses: läbipaistev protsess
- h2: Miks talvine periood on kinnisvaraturul alahinnatud
- h2: Üürilepingu indekseerimine: mida see praktikas tähendab
- h2: Kohila Kodud: uus elukeskkond loodusega piiril
- h2: Luige Keskus avas kolmanda etapi
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 30 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (defer)
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.6 KB)
**Images:** 13 total — **0 without alt**, **0 without width/height**, 0 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| nt/uploads/2026/08/padel-restate-lasnamae-valjak-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| nt/uploads/2026/08/p103-arihoone-visualisatsioon-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| content/uploads/2026/08/bts-mis-on-built-to-suit-360x240.jpg | Ehitusjärgus äripind, kraana ja pinnaset | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/arendus-tanassilma-3-etapp-360x240.jpg | Tänassilma Äripargi müügimaja õhust vaad | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/restate-siia-tuleb-tulemus-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| -content/uploads/2026/08/restate-brandi-detailid-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| te.ee/wp-content/uploads/2026/08/arendus-m-treff-360x240.jpg | M-Treff logistika- ja tööstuspark õhust | 360×240 | lazy | ✓ |
| p-content/uploads/2026/08/kodu-sisevaade-olutuba-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| -content/uploads/2026/08/pj-protsess-labipaistev-360x240.jpg | Elutoa interjöör suurte akendega | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/talvine-ohuvaade-elurajoon-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| p-content/uploads/2026/08/arendus-aaviku-aripark-360x240.jpg | Aaviku Äripargi tootmis- ja laoüksused | 360×240 | lazy | ✓ |
| ee/wp-content/uploads/2026/08/kodud-kohila-kodud-360x240.jpg | Elamupiirkond õhust sügisel | 360×240 | lazy | ✓ |
| /wp-content/uploads/2026/08/arendus-luige-keskus-360x240.jpg | Luige Keskuse kaubandushoone | 360×240 | lazy | ✓ |
**Links:** 34 anchors — 5 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "võta ühendust" ×2
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 5 pass · 0 warn · 1 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✗ fail | Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high". |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 13/13 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 27 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
- `hero: …state.ee/wp-content/uploads/2026/08/padel-restate-lasnamae-valjak-360x240.jpg`
- `loading: lazy`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 232, 233, 300, 320, 360, 465, 486, 540, 600, 640, 720, 768, 900, 960, 972, 1024, 1080, 1200, 1280, 1440, 1458, 1536, 1600, 1620, 1944, 2048, 2160`
### Priority fixes
1. **Hero image eagerly loaded** (high) — Hero image has loading="lazy", which delays LCP (inferred from DOM order/size — Lighthouse LCP element unavailable). Use loading="eager" (or omit loading) and add fetchpriority="high".
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 4 of 5 — https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos
Run: 2026-09-16T14:13:10.617Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 14653 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **85** | 99 |
| Accessibility | 96 | **95** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** / 1434 ms p75 (fast) | 0.8 s / 841 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 4 p75 (fast) |
| TBT | 0 ms | 0 ms |
| FCP | **2.00 s** / 1378 ms p75 (fast) | 644 ms / 605 ms p75 (fast) |
| Speed Index | **2.00 s** | 644 ms |
| TTFB | **6 ms** / 615 ms p75 (fast) | 4 ms / 378 ms p75 (fast) |
| INP (field only) | 119 ms p75 (fast) | 48 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **first-contentful-paint** (low) — 2.0 s
3. **document-latency-insight** (high) — Est savings of 260 ms
4. **font-display-insight** (high) — Est savings of 80 ms
5. **image-delivery-insight** (high) — Est savings of 65 KiB
### Findings (mobile)
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.47, weight 25) — Largest Contentful Paint — 4.1 s
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.84, weight 10) — First Contentful Paint — 2.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `interactive` (performance, score 0.86, weight 0) — Time to Interactive — 4.1 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 228 ms._
**Transport:**
- Final URL: https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 16 Sep 2026 14:09:32 GMT
- expires: Wed, 16 Sep 2026 14:13:10 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 25636
- Decoded body: 97.1 KB
- Compression ratio: 0.258
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 25636
content-type: text/html; charset=UTF-8
date: Wed, 16 Sep 2026 14:13:10 GMT
expires: Wed, 16 Sep 2026 14:13:10 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 16 Sep 2026 14:09:32 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 585 ms._
**Scoring:** 10 errors · 1 warnings · 45 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x7, first at line 959
2. **Attribute “preserveAspectRatio” not allowed on element “use” at this point.** (medium) — x2, first at line 576
3. **The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element.** (medium) — x1, first at line 543
### Issue groups
- (×1) [error] The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element. — first at line 543 `<img
alt="Tänassilma Äripargi laohooned õhust vaadatuna"
class="`
- (×2) [error] Attribute “preserveAspectRatio” not allowed on element “use” at this point. — first at line 576 `rue">
<use
href="https://restate.ee/wp-content/themes/restate/inc/th`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 876 `/noscript><script nowprocket type="text/javascript">var el`
- (×7) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 959 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1637 ms._
**Scoring:** 1 violations · 35 passes · critical 0 · serious 0 · moderate 1 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.footer__social`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1645 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 24 network requests · 535.0 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 5 | 363.1 KB |
| other | 3 | 53.0 KB |
| stylesheet | 5 | 46.2 KB |
| document | 2 | 25.0 KB |
| script | 4 | 23.6 KB |
| font | 2 | 16.3 KB |
| xhr | 3 | 7.7 KB |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 275 ms, 0 B
- https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos (document) — 145 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 139 ms, 0 B
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (script) — 52 ms, 2.5 KB
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 52 ms, 7.9 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1645 ms._
**Document:**
- Lang: et
- Title: Varahaldus: kuidas hoida kinnisvaraportfell töös - Restate
- Canonical: https://restate.ee/varahaldus-kuidas-hoida-kinnisvaraportfell-toos/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 98370
**Meta tags:**
- Description: Kinnisvaraportfell ei hoia end ise korras. Ülevaade sellest, millest koosneb igapäevane varahaldus ja miks see tootlust mõjutab.
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 8
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×4, h3 ×4, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Varahaldus: kuidas hoida kinnisvaraportfell töös
- h2: Üürisuhete juhtimine
- h2: Tehniline seisukord
- h2: Aruandlus omanikule
- h2: Veel artikleid
- h3: Lasnamäele tuleb uus tõmbekeskus: Peterburi teele kerkivad Padel+ Restate ja vir
- h3: Äripinna üürimine: viis asja, mida enne lepingu allkirjastamist kontrollida
- h3: Built-to-suit: kui valmis pind ettevõttele lihtsalt ei sobi
- h3: Tänassilma Äripark kasvab: kolmanda etapi ehitus on alanud
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 30 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (defer)
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 5 inline (11.5 KB)
**Images:** 5 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| content/uploads/2026/08/chess-tanassilma-aripark-360x240.jpg | Tänassilma Äripargi laohooned õhust vaad | 360×240 | eager | ✓ |
| nt/uploads/2026/08/padel-restate-lasnamae-valjak-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| nt/uploads/2026/08/p103-arihoone-visualisatsioon-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| content/uploads/2026/08/bts-mis-on-built-to-suit-360x240.jpg | Ehitusjärgus äripind, kraana ja pinnaset | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/arendus-tanassilma-3-etapp-360x240.jpg | Tänassilma Äripargi müügimaja õhust vaad | 360×240 | lazy | ✓ |
**Links:** 23 anchors — 5 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "võta ühendust" ×3
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 5/5 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
- `hero: …://restate.ee/wp-content/uploads/2026/08/chess-tanassilma-aripark-360x240.jpg`
- `loading: eager`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 360, 720, 1080, 1440`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 5 of 5 — https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida
Run: 2026-09-16T14:13:25.271Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 15084 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **81** | 99 |
| Accessibility | 96 | **95** |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.2 s** / 1434 ms p75 (fast) | 0.8 s / 841 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 4 p75 (fast) |
| TBT | 0 ms | 0 ms |
| FCP | **2.71 s** / 1378 ms p75 (fast) | 657 ms / 605 ms p75 (fast) |
| Speed Index | **3.05 s** | 657 ms |
| TTFB | 3 ms / 615 ms p75 (fast) | 3 ms / 378 ms p75 (fast) |
| INP (field only) | 119 ms p75 (fast) | 48 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.2 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **document-latency-insight** (high) — Est savings of 200 ms
4. **font-display-insight** (high) — Est savings of 50 ms
5. **image-delivery-insight** (medium) — Est savings of 128 KiB
### Findings (mobile)
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.44, weight 25) — Largest Contentful Paint — 4.2 s
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.59, weight 10) — First Contentful Paint — 2.7 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `interactive` (performance, score 0.84, weight 0) — Time to Interactive — 4.3 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 192 ms._
**Transport:**
- Final URL: https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 16 Sep 2026 14:09:34 GMT
- expires: Wed, 16 Sep 2026 14:13:25 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 25963
- Decoded body: 98.3 KB
- Compression ratio: 0.258
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **x-content-type-options missing** (medium) — Send X-Content-Type-Options: nosniff
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (missing, medium)
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 25963
content-type: text/html; charset=UTF-8
date: Wed, 16 Sep 2026 14:13:25 GMT
expires: Wed, 16 Sep 2026 14:13:25 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 16 Sep 2026 14:09:34 GMT
server: Apache / ZoneOS
vary: Accept-Encoding
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 991 ms._
**Scoring:** 10 errors · 1 warnings · 45 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x7, first at line 975
2. **Attribute “preserveAspectRatio” not allowed on element “use” at this point.** (medium) — x2, first at line 592
3. **The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element.** (medium) — x1, first at line 559
### Issue groups
- (×1) [error] The “sizes” attribute value starting with “auto” is only valid for lazy-loaded images. Add “loading=”“lazy” to this element. — first at line 559 `<img
alt=""
class="image__img"
loading="eager"
w`
- (×2) [error] Attribute “preserveAspectRatio” not allowed on element “use” at this point. — first at line 592 `rue">
<use
href="https://restate.ee/wp-content/themes/restate/inc/th`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 892 `/noscript><script nowprocket type="text/javascript">var el`
- (×7) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 975 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1616 ms._
**Scoring:** 1 violations · 35 passes · critical 0 · serious 0 · moderate 1 · minor 0
### Priority fixes
1. **landmark-unique** (medium) — Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
### Findings
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.footer__social`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 2 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1624 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 24 network requests · 641.2 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 5 | 469.0 KB |
| other | 3 | 53.0 KB |
| stylesheet | 5 | 46.2 KB |
| document | 2 | 25.4 KB |
| script | 4 | 23.6 KB |
| font | 2 | 16.3 KB |
| xhr | 3 | 7.7 KB |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 192 ms, 0 B
- https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida (document) — 172 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 137 ms, 0 B
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (script) — 57 ms, 10.1 KB
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (script) — 56 ms, 2.5 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1624 ms._
**Document:**
- Lang: et
- Title: Äripinna üürimine: viis asja, mida enne lepingu allkirjastamist kontrollida - Restate
- Canonical: https://restate.ee/aripinna-uurimine-viis-asja-mida-enne-lepingu-allkirjastamist-kontrollida/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 99612
**Meta tags:**
- Description: Üürileping seob ettevõtte pinnaga sageli viieks kuni kümneks aastaks. Panime kokku viis punkti, mis tasub enne allkirjastamist rahulikult üle käia.
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 8
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×6, h3 ×4, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Äripinna üürimine: viis asja, mida enne lepingu allkirjastamist kontrollida
- h2: 1. Tegelik kasutatav pind ja mõõtmise alus
- h2: 2. Kõrvalkulude struktuur
- h2: 3. Indekseerimine ja üüritõusu lagi
- h2: 4. Kohandustööd ja nende omanik
- h2: 5. Väljumis- ja laienemisvõimalused
- h2: Veel artikleid
- h3: Lasnamäele tuleb uus tõmbekeskus: Peterburi teele kerkivad Padel+ Restate ja vir
- h3: Built-to-suit: kui valmis pind ettevõttele lihtsalt ei sobi
- h3: Tänassilma Äripark kasvab: kolmanda etapi ehitus on alanud
- h3: Kuidas valida ettevõttele õige asukoht?
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 30 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://restate.ee/wp-content/themes/restate/inc/theme/js/core.f1e246827f6b43d8.js (defer)
- https://restate.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 5 inline (11.5 KB)
**Images:** 5 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| nt/uploads/2026/08/p103-arihoone-visualisatsioon-360x240.jpg | _(empty)_ | 360×240 | eager | ✓ |
| nt/uploads/2026/08/padel-restate-lasnamae-valjak-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
| content/uploads/2026/08/bts-mis-on-built-to-suit-360x240.jpg | Ehitusjärgus äripind, kraana ja pinnaset | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/arendus-tanassilma-3-etapp-360x240.jpg | Tänassilma Äripargi müügimaja õhust vaad | 360×240 | lazy | ✓ |
| ntent/uploads/2026/08/restate-siia-tuleb-tulemus-360x240.jpg | _(empty)_ | 360×240 | lazy | ✓ |
**Links:** 23 anchors — 5 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "võta ühendust" ×3
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 5/5 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 4 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.23.3.3`
- Hero image eagerly loaded:
- `hero: …state.ee/wp-content/uploads/2026/08/p103-arihoone-visualisatsioon-360x240.jpg`
- `loading: eager`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 360, 720, 1080, 1440`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).