Audit

20260811T065509Z-7e20

← Back to sorainencom
Audited URL
https://www.sorainen.com/et/
Timestamp
2026-08-11T07:13:13.581Z
Kind
site
Pages
10
Audit summary
https://www.sorainen.com/et/
10 of 10 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

52
Overall site quality
Poormedium confidence

Site overall 52 is the mean of 10 pages. Scores range 42 (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen) → 62 (https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year). Weakest page: Mobile performance is catastrophic (45/100) with LCP at 12.0s and 17.38 MB page weight, dragging the score heavily. Accessibility has 2 critical violations (button-name, image-alt) and 3 serious ones, failing WCAG standards. Security headers are weak (40/100) with CSP allowing unsafe-inline despite user-generated content signals. Desktop performance is strong (93) but mobile-first indexing penalizes the mobile experience. W3C validation shows 5 errors including nesting violations and missing alt attributes.

Per-page scores
46
/et
high
54
/newsroom
high
62
/et/uudised
high
48
/lv/zinas
high
55
/lt/naujienos
high
52
…the-baltics-and-belarus
high
42
…joins-law-firm-sorainen
high
54
…-lawyer-european-awards
high
62
…ers-as-bees-of-the-year
medium
46
…ion-of-patent-attorneys
high

Audit Report: Advokaadibüroo Sorainen

Website: https://www.sorainen.com/et/
Date: 11.08.2026
Audit Coverage: 99% — PageSpeed Insights (mobile): PSI HTTP 500
Confidence: medium

Pages Audited (10 of 10):

Summary of results

Overall Score: 52 / 100
Status: ⚠ 🟠 Poor

Site overall 52 is the mean of 10 pages. Scores range 42 (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen) → 62 (https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year). Weakest page: Mobile performance is catastrophic (45/100) with LCP at 12.0s and 17.38 MB page weight, dragging the score heavily. Accessibility has 2 critical violations (button-name, image-alt) and 3 serious ones, failing WCAG standards. Security headers are weak (40/100) with CSP allowing unsafe-inline despite user-generated content signals. Desktop performance is strong (93) but mobile-first indexing penalizes the mobile experience. W3C validation shows 5 errors including nesting violations and missing alt attributes.

Per-page scores

🟠 Poor · https://www.sorainen.com/et

Score Performance Accessibility Best Practices SEO Security
46 32 79 92 92 40

🟠 Poor · https://www.sorainen.com/newsroom

Score Performance Accessibility Best Practices SEO Security
54 62 85 92 85 40

🟡 Needs Improvement · https://www.sorainen.com/et/uudised

Score Performance Accessibility Best Practices SEO Security
62 67 85 92 92 40

🟠 Poor · https://www.sorainen.com/lv/zinas

Score Performance Accessibility Best Practices SEO Security
48 41 85 92 92 40

🟠 Poor · https://www.sorainen.com/lt/naujienos

Score Performance Accessibility Best Practices SEO Security
55 60 85 92 92 40

🟠 Poor · https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus

Score Performance Accessibility Best Practices SEO Security
52 67 81 92 77 40

🟠 Poor · https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen

Score Performance Accessibility Best Practices SEO Security
42 45 81 69 77 40

🟠 Poor · https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards

Score Performance Accessibility Best Practices SEO Security
54 64 78 88 77 40

🟡 Needs Improvement · https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year

Score Performance Accessibility Best Practices SEO Security
62 70 81 92 77 40

🟠 Poor · https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

Score Performance Accessibility Best Practices SEO Security
46 47 81 92 77 40

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://www.sorainen.com/et 32 / 67 10.22 s / 2.10 s 0.000 / 0.007
https://www.sorainen.com/newsroom 62 / 69 11.66 s / 1.33 s 0.000 / 0.000
https://www.sorainen.com/et/uudised 67 / 96 3.95 s / 1.24 s 0.000 / 0.000
https://www.sorainen.com/lv/zinas 41 / 75 4.71 s / 1.06 s 0.000 / 0.001
https://www.sorainen.com/lt/naujienos 60 / 78 4.82 s / 1.13 s 0.000 / 0.004
https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus 67 / 74 11.00 s / 1.40 s 0.004 / 0.003
https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen 45 / 93 11.97 s / 1.35 s 0.000 / 0.001
https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards 64 / 64 11.04 s / 960 ms 0.001 / 0.002
https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year — / 70 — / 941 ms — / 0.002
https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys 47 / 68 10.84 s / 2.10 s 0.000 / 0.000

Optimization Checklist

1 of 4 passing — 1 pass · 2 warn · 1 fail · 3 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded N/A No raster <img> elements found (4 SVGs excluded).
Hero image eagerly loaded Warn Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Fail 4 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Reduce page weight and defer third-party scripts Performance

  • Impact: LCP, TBT, FCP, Mobile Performance Score
  • Problem: Page weight is 18.44 MB (15.6 MB media) with LCP 10.2s and TBT 2.98s; recaptcha and gtag scripts cause long tasks.
  • Solution:
    • Compress/convert media (15.6 MB is excessive for a text-heavy site).
    • Defer non-critical JS (gtag, recaptcha, fb) using defer or async.
    • Implement lazy loading for below-fold images.
    • Consider removing unused scripts (154 KB wasted recaptcha JS).

1B. Add alt text and button labels Accessibility

  • Impact: WCAG 1.1.1, 4.1.2, Screen Reader Usability
  • Problem: 12 images missing alt attributes; 4 buttons lack discernible text (axe critical violations).
  • Solution:
    • Add descriptive alt text to all 12 missing images.
    • Add aria-label or visible text to .search-submit, .close, and toggle buttons.
    • Ensure decorative images use alt="".

1C. Reduce page weight and fix LCP Performance

  • Impact: LCP 11.7 s, FCP 3.1 s, Total Weight 17.4 MB
  • Problem: Page weight is 17.4 MB with 15.6 MB media; LCP is 11.7 s on mobile, far exceeding the 2.5 s threshold.
  • Solution:
    • Compress or lazy-load the 15.6 MB media asset (likely the splash video).
    • Use <video> with poster attribute and preload="metadata".
    • Implement responsive images (srcset) for raster assets.
    • Defer non-critical scripts (18 render-blocking scripts found).

1D. Fix critical form and button accessibility Accessibility

  • Impact: 5 critical axe violations (button-name, label, select-name)
  • Problem: Buttons lack discernible text; search and filter forms lack labels; 3 select elements missing accessible names.
  • Solution:
    • Add aria-label or visible text to all buttons (e.g., .search-submit).
    • Associate <label> elements with inputs using for/id.
    • Ensure <select> elements have visible labels or aria-label.

1E. Harden CSP and HSTS for UGC Security

  • Impact: XSS risk, Transport security
  • Problem: Site has user-generated content signals; CSP allows unsafe-inline/unsafe-eval; HSTS missing includeSubDomains and preload.
  • Solution:
    • Update CSP to remove unsafe-inline and unsafe-eval; use nonces/hashes.
    • Update HSTS: max-age=31536000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.

1F. Fix critical axe violations and add H1 Accessibility

  • Impact: WCAG compliance, SEO structure
  • Problem: 3 critical axe violations (button-name, label, select-name) and 0 h1 elements found; 18 form inputs lack labels.
  • Solution:
    • Add exactly one <h1> to the page (currently missing).
    • Add aria-label or visible text to all buttons (e.g., .search-submit).
    • Add <label> elements or aria-label to all form inputs (search, select, checkboxes).
    • Ensure <select> elements have associated labels.

1G. Defer render-blocking scripts Performance

  • Impact: FCP, TBT, LCP
  • Problem: 18 render-blocking scripts in <head> delay FCP to 3.1 s and contribute to TBT 486 ms.
  • Solution:
    • Add defer or async to non-critical scripts in <head>.
    • Move analytics/tracking scripts (GTM, Facebook Pixel) to the footer or load via defer.
    • Example: <script src="..." defer></script>

1H. Reduce page weight and defer non-critical scripts Performance

  • Impact: LCP, TBT, FCP, Mobile Performance Score
  • Problem: Page weight is 17.4 MB (15.6 MB video) with 18 render-blocking scripts; LCP is 4.7 s and TBT is 2.98 s.
  • Solution:
    • Replace the 15.6 MB splash.webm with a lightweight poster image or lazy-load the video.
    • Add defer or async to the 18 render-blocking scripts (e.g., jQuery, GTM, Facebook Pixel).
    • Remove unused JavaScript (154 KB recaptcha, 71 KB gtag).

1I. Fix critical form and button accessibility issues Accessibility

  • Impact: WCAG 2.1 Level A compliance, Screen Reader usability
  • Problem: 3 critical axe violations: buttons lack discernible text, search/select forms lack labels.
  • Solution:
    • Add aria-label or visible text to all buttons (e.g., .search-submit).
    • Associate <label> elements with all form inputs (search, filters, newsletter).
    • Ensure <select> elements have accessible names.

1J. Optimize Largest Contentful Paint (LCP) Performance

  • Impact: LCP, FCP, TBT
  • Problem: Mobile LCP is 4.8s (heavy penalty) and FCP is 3.07s, driven by render-blocking scripts and heavy third-party JS (recaptcha, gtag).
  • Solution:
    • Defer non-critical scripts (e.g., GTM, Facebook Pixel) until after main content renders.
    • Preload LCP image if it is an image element.
    • Reduce TBT by splitting long tasks in third-party scripts or loading them asynchronously.

1K. Fix Critical Form and Button Labels Accessibility

  • Impact: WCAG 2.1.1, 4.1.2
  • Problem: 3 critical axe violations: buttons lack discernible text, form elements (search, select) lack labels.
  • Solution:
    • Add aria-label or visible text to all buttons (e.g., .search-submit).
    • Associate <label> elements with all form inputs using for and id attributes.
    • Ensure <select> elements have accessible names.

1L. Reduce page weight and optimize media Performance

  • Impact: LCP, FCP, Total Page Weight
  • Problem: Browser runtime shows 17.38 MB total weight with 15.61 MB from media; LCP is 11.0 s on mobile.
  • Solution:
    • Compress and convert video assets (splash.webm failed to load).
    • Implement lazy loading for off-screen images.
    • Use modern formats (WebP/AVIF) and responsive srcset.
    • Consider a CDN for static assets.

1M. Fix critical axe-core violations Accessibility

  • Impact: WCAG 2.1 Compliance, Screen Reader Support
  • Problem: 2 critical violations: button-name (search-submit) and image-alt (newsIntro) missing accessible names.
  • Solution:
    • Add aria-label or visible text to .search-submit button.
    • Add descriptive alt text to .newsIntro__line--2 image.
    • Ensure all interactive elements have discernible names.

1N. Reduce media weight and fix LCP Performance

  • Impact: LCP, FCP, Page Weight
  • Problem: Mobile LCP is 12.0s and total page weight is 17.38 MB (15.61 MB media), causing severe load delays.
  • Solution:
    • Compress or lazy-load the 15.61 MB video asset (splash.webm).
    • Use fetchpriority="high" on the LCP image.
    • Implement responsive images (srcset) to serve smaller files on mobile.

1O. Fix critical axe violations Accessibility

  • Impact: WCAG 2.1 Compliance
  • Problem: 2 critical violations found: button-name (search-submit) and image-alt (content images missing text).
  • Solution:
    • Add aria-label or visible text to .search-submit button.
    • Add descriptive alt text to all <img> elements, especially .newsIntro__line--2.

1P. Harden Content Security Policy Security

  • Impact: XSS Defense
  • Problem: CSP allows unsafe-inline and unsafe-eval scripts, which defeats XSS protection despite UGC signals.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from script-src.
    • Use nonces or hashes for allowed scripts (e.g., script-src 'nonce-{random}').
    • Ensure hello.myfonts.net is whitelisted in connect-src to fix console errors.

1Q. Reduce media weight and optimize LCP Performance

  • Impact: LCP, Page Weight, Mobile Performance
  • Problem: Browser Runtime shows 15.61 MB media weight (17.39 MB total); Mobile LCP is 11.0 s (Desktop 1.0 s).
  • Solution:
    • Compress video/images aggressively (target <5 MB total).
    • Use fetchpriority="high" on the LCP image.
    • Implement responsive images (srcset) to serve smaller files to mobile.
    • Preload the LCP resource.

1R. Fix critical axe violations (button, image) Accessibility

  • Impact: WCAG 2.1 Compliance, Screen Reader Support
  • Problem: 2 critical violations: button-name (search-submit) and image-alt (2 images missing alt).
  • Solution:
    • Add aria-label or visible text to .search-submit.
    • Add descriptive alt text to all content images (e.g., alt="Karolina Sorainen").
    • Ensure decorative images use alt="".

1S. Harden CSP and HSTS for UGC site Security

  • Impact: XSS Protection, Transport Security
  • Problem: CSP allows unsafe-inline/unsafe-eval (high risk with UGC signal); HSTS missing includeSubDomains/preload. Grade 40/100.
  • Solution:
    • Remove unsafe-inline and unsafe-eval from CSP; use nonces/hashes.
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.
    • Add X-Content-Type-Options: nosniff (already present, verify strictness).

1T. Fix critical accessibility violations (alt text, button names) Accessibility

  • Impact: WCAG compliance, screen reader usability
  • Problem: axe-core reports 2 critical violations: 2 images missing alt attributes and 2 buttons without discernible text.
  • Solution:
    • Add descriptive alt text to all content images (e.g., <img src="..." alt="Sorainen lawyers receiving award">).
    • Ensure all buttons have visible text or aria-label (e.g., <button aria-label="Submit search">).

1U. Reduce media payload (15.61 MB video/images) Performance

  • Impact: Page load time, data usage, LCP stability
  • Problem: Browser runtime shows 17.38 MB total weight, with 15.61 MB from a single media asset (likely video). This is excessive for a news article page.
  • Solution:
    • Compress video assets (use WebM/MP4 with lower bitrate) or serve poster images instead of autoplaying video.
    • Implement lazy loading for off-screen media (loading="lazy").
    • Consider using a CDN for video delivery.

1V. Harden Content Security Policy (remove unsafe-inline/eval) Security

  • Impact: XSS protection, data integrity
  • Problem: CSP allows unsafe-inline and unsafe-eval, negating XSS protection. Site signals indicate user-generated content ('post' anchor), raising XSS risk.
  • Solution:
    • Audit third-party scripts (GTM, Recaptcha, Facebook) to use nonces or hashes instead of unsafe-inline.
    • Implement a strict CSP with 'strict-dynamic' and nonces for allowed scripts.
    • Example: script-src 'nonce-{random}' 'strict-dynamic';

1W. Reduce media weight and fix failed video request Performance

  • Impact: LCP, TBT, Page Weight
  • Problem: Total page weight is 17.38 MB with 15.61 MB from media; LCP is 10.8 s on mobile. A video splash.webm request failed (net::ERR_ABORTED).
  • Solution:
    • Compress or lazy-load the video splash asset.
    • Use <video> with preload="metadata" and poster image.
    • Ensure the video file exists at /wp-content/themes/sorainen/build/video/splash.webm.

1X. Fix critical axe violations (buttons, images, contrast) Accessibility

  • Impact: WCAG 2.1 A/AA Compliance
  • Problem: 2 critical violations: buttons lack discernible text (.search-submit), images lack alt text (.newsIntro__line--2). 3 serious violations on color contrast.
  • Solution:
    • Add aria-label or visible text to .search-submit and .col-tp-none.
    • Add descriptive alt text to all content images.
    • Increase contrast ratio for menu links to ≥4.5:1.

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Harden Content Security Policy and HSTS Security

  • Impact: XSS Defense, Transport Security
  • Problem: CSP allows unsafe-inline and unsafe-eval (high risk); HSTS missing includeSubDomains and preload.
  • Solution:
    • Remove unsafe-inline and unsafe-eval from CSP; use nonces/hashes for scripts.
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.

2B. Enable user zoom and fix viewport Accessibility

  • Impact: WCAG 1.4.4, Mobile Usability
  • Problem: Viewport meta tag sets user-scalable=no and maximum-scale=1.0, blocking zoom.
  • Solution:
    • Update viewport meta tag: <meta name="viewport" content="width=device-width, initial-scale=1.0">.
    • Ensure touch targets meet 44x44px minimum size.

2C. Add H1 and Meta Description SEO

  • Impact: Search visibility, Document outline
  • Problem: Document has 0 <h1> elements and no meta description; 10 W3C errors including duplicate IDs.
  • Solution:
    • Add a unique <h1> describing the page content.
    • Add <meta name="description" content="...">.
    • Fix duplicate IDs (e.g., select-50-8002b801-adc4a003) and invalid attributes (stylr).

2D. Defer render-blocking scripts Performance

  • Impact: FCP, TBT
  • Problem: 18 render-blocking scripts found; 4 in <head> blocking rendering.
  • Solution:
    • Add defer or async to non-critical scripts.
    • Move analytics and third-party tags to footer or use type="module".
    • Remove unused JS (164 KB wasted on reCAPTCHA, 71 KB on GTM).

2E. Fix CSP to allow GTM and Fonts without unsafe-inline Security

  • Impact: XSS protection, resource loading
  • Problem: CSP blocks GTM images and fonts (console errors) while allowing unsafe-inline and unsafe-eval, defeating XSS protection.
  • Solution:
    • Remove unsafe-inline and unsafe-eval from script-src.
    • Add specific nonces or hashes for allowed scripts.
    • Add https://www.googletagmanager.com and https://fonts.gstatic.com to img-src and connect-src to stop console errors.

2F. Optimize video asset Performance

  • Impact: Page weight, LCP
  • Problem: Media resource splash.webm is 15.6 MB, contributing to 17.4 MB total page weight and LCP 3.9 s.
  • Solution:
    • Compress video to <5 MB using H.264/VP9.
    • Serve via a CDN with adaptive bitrate streaming.
    • Use poster attribute for instant visual feedback before load.

2G. Strengthen HSTS and add missing headers Security

  • Impact: Transport security, privacy
  • Problem: HSTS missing includeSubDomains and preload; Referrer-Policy, COOP, CORP missing.
  • Solution:
    • Update HSTS: max-age=31536000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.
    • Add Permissions-Policy to disable unused features.

2H. Fix HTML structure and W3C validation errors SEO

  • Impact: Search ranking, Document outline, CLS
  • Problem: No <h1> element, 12 W3C errors (duplicate IDs, invalid attributes), 4 images missing dimensions.
  • Solution:
    • Add a single <h1> describing the page content.
    • Fix duplicate IDs (e.g., select-50-8002b801-ae3c5c07).
    • Add width and height attributes to all <img> tags to prevent CLS.

2I. Strengthen HSTS and CSP Headers Security

  • Impact: Transport security, XSS mitigation
  • Problem: HSTS missing includeSubDomains and preload; CSP allows unsafe-inline and unsafe-eval.
  • Solution:
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    • Refine CSP to remove unsafe-inline/unsafe-eval where possible, or use nonces for scripts.

2J. Harden Content Security Policy (CSP) Security

  • Impact: XSS Defense, Data Integrity
  • Problem: CSP allows unsafe-inline and unsafe-eval, negating XSS protection; UGC signal is present.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from script-src.
    • Use nonces or hashes for allowed scripts.
    • Ensure connect-src includes hello.myfonts.net to stop console errors.

2K. Fix contrast, viewport, and link names Accessibility

  • Impact: WCAG 1.4.3, 1.4.4, 2.4.4
  • Problem: Serious violations: color-contrast (menu links), meta-viewport (user-scalable=no), link-name (social icons).
  • Solution:
    • Increase contrast ratio to ≥4.5:1 for menu links.
    • Remove user-scalable=no from viewport meta tag.
    • Add aria-label to icon-only links (e.g., aria-label="Share on LinkedIn").

2L. Reduce Total Blocking Time (TBT) by deferring scripts Performance

  • Impact: Interactivity, TBT metric
  • Problem: TBT is 692 ms (warning threshold >600 ms) caused by long tasks from Google Tag Manager, Recaptcha, and Facebook Pixel.
  • Solution:
    • Defer non-critical scripts (analytics, pixels) until after load or requestIdleCallback.
    • Use async or defer attributes on script tags where possible.
    • Consider loading Recaptcha only on form interaction.

2M. Fix W3C validation errors and missing landmarks Best Practices

  • Impact: SEO, semantic structure, parser recovery
  • Problem: W3C reports 6 errors including missing alt, illegal href characters, and nesting violations. main landmark is missing.
  • Solution:
    • Wrap main content in <main> tag.
    • Fix nesting errors (e.g., <a> inside <a>).
    • Encode special characters in URLs (e.g., spaces in href).

2N. Defer render-blocking JavaScript Performance

  • Impact: FCP, TBT
  • Problem: 16 render-blocking scripts detected in <head>. 4 scripts specifically flagged in optimization checklist (jQuery, GTM, Facebook Pixel, CookieYes).
  • Solution:
    • Add defer or async to non-critical scripts.
    • Move analytics and tracking scripts to the footer.
    • Inline critical CSS and defer non-critical CSS.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Fix HTML validation errors and nesting Best Practices

  • Impact: Maintainability, SEO Crawling
  • Problem: 16 W3C errors including missing alt, bad href, and anchor nesting violations.
  • Solution:
    • Fix empty href attributes on <link> tags.
    • Resolve anchor nesting errors (e.g., <a> inside <a>).
    • Add main landmark and skip-to-content link.

3B. Fix HTML Validation Errors Best Practices

  • Impact: Maintainability, rendering consistency
  • Problem: 12 W3C errors including duplicate IDs (e.g., select-finansai-ir-draudimas) and invalid attributes.
  • Solution:
    • Ensure all IDs are unique within the document.
    • Remove invalid attributes (e.g., stylr on <a>, pause on <video>).
    • Fix attribute spacing errors.

3C. Add meta description and fix HTML errors SEO

  • Impact: Search Snippets, Validation
  • Problem: Meta description missing; W3C reports 5 errors including illegal characters in href and nesting violations.
  • Solution:
    • Add <meta name="description" content="...">.
    • Fix href query strings (remove spaces).
    • Correct <a> tag nesting in the author section.

3D. Add meta description and fix W3C errors SEO

  • Impact: Search Snippets, Validation
  • Problem: Missing meta description; 20 W3C errors (unknown o_p elements, nesting issues).
  • Solution:
    • Write a 150-character meta description.
    • Remove custom o_p elements; use standard HTML.
    • Fix anchor nesting errors (line 311).

3E. Add meta description and fix HSTS directives SEO

  • Impact: Search snippet, transport security
  • Problem: SEO audit shows missing meta description. HSTS header lacks includeSubDomains and preload directives.
  • Solution:
    • Add <meta name="description" content="..."> summarizing the article.
    • Update HSTS header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload.

3F. Fix HTML validation errors and meta description SEO

  • Impact: SEO, Crawlability
  • Problem: W3C validator reports 5 errors (bad href, missing img alt, nesting). Meta description is not set.
  • Solution:
    • Add meta name="description" with relevant text.
    • Fix <a> href query string spaces (URL encode).
    • Ensure <img> tags have alt and fix nesting violations.
▸Raw Markdown sent to the LLM
# Site Audit — https://www.sorainen.com/et/
Run: 2026-08-11T07:02:45.402Z

Audited **10** of 10 discovered pages.
Average per-page audit coverage: **99%**

Aggregate missing or failed sources (deduped across pages):
- PageSpeed Insights (mobile): PSI HTTP 500

Pages audited:
- https://www.sorainen.com/et
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

---

# Page 1 of 10 — https://www.sorainen.com/et

Run: 2026-08-11T07:02:49.608Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 42613 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **32** | 67 |
| Accessibility | 79 | 79 |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.2 s** / 1389 ms p75 (fast) | 2.1 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.007** / 0 p75 (fast) |
| TBT | **2.98 s** | 433 ms |
| FCP | **3.05 s** / 1134 ms p75 (fast) | 791 ms / 924 ms p75 (fast) |
| Speed Index | **9.96 s** | 1.92 s |
| TTFB | 3 ms / 690 ms p75 (fast) | 3 ms / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (high) — 2,980 ms
2. **largest-contentful-paint** (high) — 10.2 s
3. **speed-index** (high) — 10.0 s
4. **first-contentful-paint** (high) — 3.0 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 73 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 38 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 626 ms
- https://connect.facebook.net/en_US/fbevents.js — 501 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 462 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 400 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 387 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 327 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 234 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 202 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 167 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 161 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.03, weight 30) — Total Blocking Time — 2,980 ms
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.2 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `speed-index` (performance, score 0.09, weight 10) — Speed Index — 10.0 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.03, weight 0) — Time to Interactive — 18.1 s
- `max-potential-fid` (performance, score 0.03, weight 0) — Max Potential First Input Delay — 630 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 360 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 06:44:25 GMT
- expires: Tue, 11 Aug 2026 07:02:49 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16467
- Decoded body: 69.9 KB
- Compression ratio: 0.23

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16467
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:02:49 GMT
expires: Tue, 11 Aug 2026 07:02:49 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 06:44:25 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1190 ms._

**Scoring:** 16 errors · 9 warnings · 35 cosmetic (suppressed)

> **Validator truncated at line 410** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 410** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (high) — x12, first at line 258
3. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 54
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 410
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 410

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 54 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 104 `33;" />
		<script type="text/javascript">
			(f`
- (×12) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 258 `<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/img/line__ho`
- (×2) [warning] Empty heading. — first at line 275 `<h2></h2>`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 337 `<section class="homePeople bg-purple">
			<d`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 410 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`
- (×1) [error] End tag “a” violates nesting rules. — first at line 410 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 410 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3811 ms._

**Scoring:** 8 violations · 49 passes · critical 2 · serious 3 · moderate 2 · minor 1

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.headerSearch__toggle.col-tp-none.col-m-none`
- `.submit`
- `.close`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `.current_page_parent > a`
- … and 5 more nodes

#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `#slick-slide00 > a[target="_self"] > .homeHeroSlider__main > h2`

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.homeHero__line1`
- `.homeHero__line2`
- `.line__homePeople_1`
- `.line__homePeople_2`
- `.line__homePeople_3`
- … and 3 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.searchBar > .container > .btn-close.btn[href="javascript:;"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 1 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `h1`
- `.homeHero__line1`
- `.homeHero__quote`
- … and 20 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3825 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 80 network requests · 18.44 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 25 | 1.18 MB |
| image | 27 | 1.12 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| document | 3 | 16.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 671 ms, 668 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 413 ms, 331.9 KB
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 374 ms, 2 B
- https://www.sorainen.com/et (document) — 363 ms, 0 B
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/gyv-PJ7q.json (fetch) — 303 ms, 44 B

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431770111&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=1555722540&_eu=AAAAAGAC&are=1&cid=1265748856.1786431771&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896803~120125305&sid=1786431770&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1181 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431770111&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=1555722540&_eu=AAAAAGAC&are=1&cid=1265748856.1786431771&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896803~120125305&sid=1786431770&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1181 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=are72lq9ox5m)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=are72lq9ox5m)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3825 ms._

**Document:**
- Lang: et
- Title: Advokaadibüroo Sorainen
- Canonical: https://www.sorainen.com/et/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 113921

**Meta tags:**
- Description: Oleme äriõigusele keskendunud regionaalne advokaadibüroo, kus Eesti, Läti ja Leedu kontorid tegutsevad ühtse tervikuna.
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×6, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Aitame klientidel olla äris edukad
  - h2: 
  - h2: 
  - h2: Eesti edu võti on kiirus ja vägevad põlvkonnad
  - h2: Meiega liitus Eesti tuntumaid ja kogenumaid tehingunõustajaid Sven Papp
  - h2: Värsked edetabelid kinnitavad meie positsiooni Baltikumi tippbüroona
  - h2: Nõustamisvaldkonnad
  - h3: Eva Berlaus, juhtivpartner
  - h3: Eva Berlaus, juhtivpartner
  - h2: Uudised
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
  - h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 46 total — 1 defer, 6 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 6 inline (26.6 KB)

**Images:** 21 total — **12 without alt**, **16 without width/height**, 19 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_2.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ent/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif | _(empty)_ | 1142×1243 | _n/a_ | ✗ |
| wp-content/uploads/2025/11/new-horizons-with-sorainen-ee.png | Tekst: „Koos jõuame kaugemale – aitame e | 1142×1243 | _n/a_ | ✓ |
| uploads/2026/07/soraineni-sagedus-edukas-eesti-thumbnail.png | Soraineni Sagedus Edukas Eesti Kaupo Lep | 1080×1080 | _n/a_ | ✓ |
| m/wp-content/uploads/2026/04/sven-papp-ee-web-front-page.png | Ühinemiste ja ülevõtmiste, ühingu- ja tö | 1142×1243 | lazy | ✓ |
| nd-legal-500-2026-campaign-web-first-page-1142-x-1243-px.png | Top tier firm. Legal500. Chambers top ra | 1142×1243 | lazy | ✓ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| /wp-content/themes/sorainen/build/img/line__homePeople_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/line__homePeople_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 73 anchors — 8 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "nõustamisvaldkonnad" ×5
- "uudised" ×3
- "sorainen" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "näita kõiki uudiseid" ×2
- "eva berlaus" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- search — **no label**
Form 3:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **12 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
3. **16 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **16 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (16 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/5 raster images use srcset or <picture> (80%) (16 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 11 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: …ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.expertiseIntro__img.bg-cover`
  - `url: ….sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-scaled.jpg`
  - `box: 419×624px`
- Responsive images (srcset / <picture>):
  - `…ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
- Reasonable number of image sizes:
  - `widths: 46, 50, 150, 240, 310, 500, 541, 589, 768, 1080, 1142`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 10 — https://www.sorainen.com/newsroom

Run: 2026-08-11T07:02:49.610Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 23305 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **62** | 69 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.7 s** / 1389 ms p75 (fast) | 1.3 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | 276 ms | **567 ms** |
| FCP | **3.10 s** / 1134 ms p75 (fast) | 838 ms / 924 ms p75 (fast) |
| Speed Index | **3.94 s** | 2.04 s |
| TTFB | **13 ms** / 690 ms p75 (fast) | 12 ms / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 11.7 s
2. **total-blocking-time** (low) — 280 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (low) — 3.9 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 127 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 122 ms
- https://connect.facebook.net/en_US/fbevents.js — 112 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 111 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 73 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 71 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 67 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 63 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 62 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 58 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.7 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `total-blocking-time` (performance, score 0.81, weight 30) — Total Blocking Time — 280 ms
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.82, weight 10) — Speed Index — 3.9 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `interactive` (performance, score 0.13, weight 0) — Time to Interactive — 13.0 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 389 ms._

**Transport:**
- Final URL: https://www.sorainen.com/newsroom/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:00:54 GMT
- expires: Tue, 11 Aug 2026 07:02:49 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19207
- Decoded body: 79.7 KB
- Compression ratio: 0.235

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 19207
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:02:49 GMT
expires: Tue, 11 Aug 2026 07:02:49 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 10 Aug 2026 16:00:54 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1273 ms._

**Scoring:** 10 errors · 15 warnings · 76 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-adc4a003”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-insurance”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-50-8002b801-adc4a006”.** (medium) — x1, first at line 356

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/newsletter/" class="btn btn-primary btn-primar`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a003”. — first at line 356 `s</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a003” was here. — first at line 356 `g</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [error] Duplicate ID “select-insurance”. — first at line 356 `s</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [warning] The first occurrence of ID “select-insurance” was here. — first at line 356 `t</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a006”. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a006” was here. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c0d”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c0d” was here. — first at line 356 `n</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 452 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 457 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">No res`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3810 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3827 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.41 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 18.8 KB |
| xhr | 2 | 2.7 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=en&order=DESC&orderby=date&currentPage=2 (xhr) — 524 ms, 2.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 468 ms, 137.9 KB
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (script) — 467 ms, 862 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 462 ms, 331.9 KB
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 400 ms, 663 B

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431770084&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2098011279&_eu=AAAAAGAC&are=1&cid=818878926.1786431771&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=16&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118395334~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786431770&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1238 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431770084&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2098011279&_eu=AAAAAGAC&are=1&cid=818878926.1786431771&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=16&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118395334~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786431770&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1238 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=8nz1q7l9kq3x)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=8nz1q7l9kq3x)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3827 ms._

**Document:**
- Lang: en-US
- Title: Newsroom - Sorainen
- Canonical: https://www.sorainen.com/newsroom/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 133851

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: No results
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: Sorainen awarded IFLR Baltic Law Firm of the Year 2026 for record 10th time for 
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h3: Sorainen awarded Baltic Law Firm of the Year at the Chambers Europe 2026 ceremon
  - h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
  - h3: We strengthen Dispute Resolution and ESG capabilities with the addition of attor
  - h3: Baltic Deals of the Year 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Join our newsletter!
  - h3: Search news
  - h3: Keyword
  - h3: Sector
  - h3: Service
  - h3: Country
  - h3: Date
  - h3: Date
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 6 inline (26.6 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 93 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×6
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "saulė dagilytė" ×2
- "laimonas skibarka" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 10 — https://www.sorainen.com/et/uudised

Run: 2026-08-11T07:03:12.916Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 21203 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 96 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.9 s** / 1389 ms p75 (fast) | 1.2 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **486 ms** | 43 ms |
| FCP | **3.10 s** / 1134 ms p75 (fast) | 830 ms / 924 ms p75 (fast) |
| Speed Index | **4.89 s** | 1.24 s |
| TTFB | 14 ms / 690 ms p75 (fast) | 14 ms / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (medium) — 490 ms
2. **largest-contentful-paint** (medium) — 3.9 s
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.9 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 161 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 167 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 159 ms
- https://connect.facebook.net/en_US/fbevents.js — 147 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 134 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 97 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 92 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 87 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 82 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 79 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.59, weight 30) — Total Blocking Time — 490 ms
- `largest-contentful-paint` (performance, score 0.51, weight 25) — Largest Contentful Paint — 3.9 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.65, weight 10) — Speed Index — 4.9 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.2 s
- `max-potential-fid` (performance, score 0.78, weight 0) — Max Potential First Input Delay — 170 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 452 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/uudised/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 02:12:18 GMT
- expires: Tue, 11 Aug 2026 07:03:13 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 20200
- Decoded body: 82.2 KB
- Compression ratio: 0.24

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 20200
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:03:13 GMT
expires: Tue, 11 Aug 2026 07:03:13 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 02:12:18 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1224 ms._

**Scoring:** 8 errors · 12 warnings · 79 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 359
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 54
3. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 357
4. **Duplicate ID “select-kapitaliturud”.** (medium) — x1, first at line 359
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 459

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 54 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 100 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 357 `<a href="https://www.sorainen.com/et/uudiskiri/" class="btn btn-primary btn-prim`
- (×3) [error] No space between attributes. — first at line 359 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-kapitaliturud”. — first at line 359 `)</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [warning] The first occurrence of ID “select-kapitaliturud” was here. — first at line 359 `s</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 459 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 464 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 268 `<h2 class="postsEmpty__title">Tulemu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3380 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `#footer-menu > .current_page_parent.current_page_parent-type-post_type.current_page_parent-object-page > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3396 ms._

**Capture summary:** 14 console events · 0 mixed-content requests · 66 network requests · 17.41 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.7 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=et&order=DESC&orderby=date&currentPage=2 (xhr) — 511 ms, 3.1 KB
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 490 ms, 668 B
- https://www.sorainen.com/et/uudised (document) — 444 ms, 0 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 376 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 260 ms, 331.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.init&eid=5&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
3. **failed request** (medium) — image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=6&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
4. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.init&eid=5&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.
5. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=6&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.
6. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=7&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&hf=0__html.0__html&ht=p__html.p__html&tr=1googtag.1cvt.1cvt.1gaawe.1cl.1cl.1lcl.1lcl.1lcl.1tl.1tl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1cl.1evl.1html.1html&ti=2googtag.2cvt.2cvt.2gaawe.2cl.2cl.2lcl.2lcl.2lcl.2tl.2tl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2cl.2evl.2html.2html&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.
7. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=13&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.init&eid=5&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=6&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=7&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&hf=0__html.0__html&ht=p__html.p__html&tr=1googtag.1cvt.1cvt.1gaawe.1cl.1cl.1lcl.1lcl.1lcl.1tl.1tl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1cl.1evl.1html.1html&ti=2googtag.2cvt.2cvt.2gaawe.2cl.2cl.2lcl.2lcl.2lcl.2tl.2tl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2cl.2evl.2html.2html&z=0 — csp
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=13&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.dom&eid=14&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431793455&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=734758978&_eu=AAAAAGAC&are=1&cid=150653071.1786431794&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118897920~118897930~119259606~119367802~119367810~119527019~119896802&sid=1786431793&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Uudised%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=978 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- image: https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.historyChange-v2&eid=24&u=AgAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.init&eid=5&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=6&u=AAAAAIACAAAAAACAAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=7&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&hf=0__html.0__html&ht=p__html.p__html&tr=1googtag.1cvt.1cvt.1gaawe.1cl.1cl.1lcl.1lcl.1lcl.1tl.1tl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1lcl.1cl.1evl.1html.1html&ti=2googtag.2cvt.2cvt.2gaawe.2cl.2cl.2lcl.2lcl.2lcl.2tl.2tl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2lcl.2cl.2evl.2html.2html&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=*&eid=13&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.dom&eid=14&u=AAAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=z9nhh8v4uf33)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Loading the image 'https://www.googletagmanager.com/a?id=GTM-TP84RL9&v=3&t=t&pid=1810773737&gtm=45He6871v835828663za200zd835828663&cv=69&rv=6871&tc=74&tag_exp=115938465~115938468~118897920~118897930~119259606~119527020~119896802~120125304&es=1&e=gtm.historyChange-v2&eid=24&u=AgAAAIAKAAAAAACIAAAAAAAY&ut=AAAI&h=Ag&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/et/uudised/)
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=z9nhh8v4uf33)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3396 ms._

**Document:**
- Lang: et
- Title: Uudised - Sorainen
- Canonical: https://www.sorainen.com/et/uudised/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 136539

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Tulemusi ei leitud
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
  - h3: Kohaliku omavalitsuse uudised: olulised muudatused ehituses, hariduses ja tarist
  - h3: Sorainen valiti Chambers Europe 2026 galal Balti riikide aasta advokaadibürooks
  - h3: Eduka Eesti võitis idee luua Eesti ettevõtete kaitseliit
  - h3: 2026. aasta suurtehingud tegid Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Maksu-uudised: vabatahtlik reserv omakapitali sissemaksena, Eesti maksutahtest j
  - h3: Meie partneriteringiga on liitunud Eesti tuntumaid ja kogenumaid tehingunõustaja
  - h3: Soovid meie uudiskirju?
  - h3: Otsi uudiseid
  - h3: Märksõna
  - h3: Ärivaldkond
  - h3: Õigusvaldkond
  - h3: Riik
  - h3: Kuupäev
  - h3: Kuupäev
  - h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 87 anchors — 8 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×4
- "uudised" ×3
- "kaupo lepasepp" ×3
- "sorainen" ×2
- "nõustamisvaldkonnad" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "iris magnus" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 10 — https://www.sorainen.com/lv/zinas

Run: 2026-08-11T07:03:32.221Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 80656 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **41** | 75 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.7 s** / 1389 ms p75 (fast) | 1.1 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | **2.98 s** | 467 ms |
| FCP | **3.03 s** / 1134 ms p75 (fast) | 802 ms / 924 ms p75 (fast) |
| Speed Index | **7.69 s** | 1.66 s |
| TTFB | **3 ms** / 690 ms p75 (fast) | 2 ms / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (high) — 2,980 ms
2. **largest-contentful-paint** (high) — 4.7 s
3. **speed-index** (high) — 7.7 s
4. **first-contentful-paint** (high) — 3.0 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 152 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 709 ms
- https://connect.facebook.net/en_US/fbevents.js — 412 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 356 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 276 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 253 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 242 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 223 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 207 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 196 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 150 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.03, weight 30) — Total Blocking Time — 2,980 ms
- `largest-contentful-paint` (performance, score 0.32, weight 25) — Largest Contentful Paint — 4.7 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `speed-index` (performance, score 0.25, weight 10) — Speed Index — 7.7 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `max-potential-fid` (performance, score 0.02, weight 0) — Max Potential First Input Delay — 710 ms
- `interactive` (performance, score 0.08, weight 0) — Time to Interactive — 14.8 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 371 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lv/zinas/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 08:58:35 GMT
- expires: Tue, 11 Aug 2026 07:03:32 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19590
- Decoded body: 80.8 KB
- Compression ratio: 0.237

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19590
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:03:32 GMT
expires: Tue, 11 Aug 2026 07:03:32 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 08:58:35 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1158 ms._

**Scoring:** 12 errors · 17 warnings · 83 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-ae3c5c07”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-finanses-un-apdrosinasana”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-kapitala-tirgi”.** (medium) — x1, first at line 356

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/lv/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c07”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c07” was here. — first at line 356 `a</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [error] Duplicate ID “select-finanses-un-apdrosinasana”. — first at line 356 `a</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [warning] The first occurrence of ID “select-finanses-un-apdrosinasana” was here. — first at line 356 `i</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [error] Duplicate ID “select-kapitala-tirgi”. — first at line 356 `)</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [warning] The first occurrence of ID “select-kapitala-tirgi” was here. — first at line 356 `a</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [error] Duplicate ID “select-nekustamais-ipasums-un-buvnieciba”. — first at line 356 `a</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums-un-buvnieciba” was here. — first at line 356 `i</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [error] Duplicate ID “select-buvnieciba”. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [warning] The first occurrence of ID “select-buvnieciba” was here. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [error] Duplicate ID “select-nekustamais-ipasums”. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums” was here. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 455 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 460 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">Nekas`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3381 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5485 > a`
- `#menu-item-5486 > a`
- `#menu-item-115921 > a`
- `#footer-menu > .menu-item-104920.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5489 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3394 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.41 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.1 KB |
| xhr | 2 | 3.0 KB |
| fetch | 8 | 809 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 903 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lv&order=DESC&orderby=date&currentPage=2 (xhr) — 462 ms, 3.0 KB
- https://www.sorainen.com/lv/zinas (document) — 399 ms, 0 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/feedback/schema (fetch) — 381 ms, 763 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/refill (fetch) — 354 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 241 ms, 331.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431812713&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1664929159&_eu=AAAAAGAC&are=1&cid=117894538.1786431813&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119404700~119527020~119896803&sid=1786431813&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=911 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431812713&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1664929159&_eu=AAAAAGAC&are=1&cid=117894538.1786431813&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119404700~119527020~119896803&sid=1786431813&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=911 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=bz2esg4n1ysm)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=bz2esg4n1ysm)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3393 ms._

**Document:**
- Lang: lv-LV
- Title: Ziņas - Sorainen
- Canonical: https://www.sorainen.com/lv/zinas/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 133890

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nekas netika atrasts
  - h3: Palīdzam privātajiem klientiem aizsargāt un vairot kapitālu: Chambers reitingā S
  - h3: Sorainen publicē Ilgtspējas ziņojumu 2026: atbildīga izaugsme un disciplinēts pr
  - h3: iFinanses.lv: Kādos autopārvadājumos no 1. jūlija nepieciešams tahogrāfs?
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen kļūst par “Liepāja 2027” juridisko partneri ceļā uz Eiropas kultūras ga
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen ir atzīts par Gada advokātu biroju Baltijā Chambers Europe 2026 apbalvo
  - h3: Sorainen kļūst par Latvijas E‑komercijas Asociācijas sadarbības partneri
  - h3: Sorainen turpina atbalstīt Rīgas Juridiskās augstskolas bibliotēku
  - h3: Baltijas gada darījumi 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCap 
  - h3: Piesakieties jaunumiem!
  - h3: Meklēt ziņas
  - h3: Atslēgvārds
  - h3: Sektors
  - h3: Pakalpojums
  - h3: Valsts
  - h3: Datums
  - h3: Datums
  - h4: Vai jūs interesē juridiskie jaunumi reģionā?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 73 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "ziņas" ×3
- "sorainen" ×2
- "specializācija" ×2
- "komanda" ×2
- "karjera" ×2
- "par mums" ×2
- "kontakti" ×2
- "augustas klezys" ×2
- "piret jesse" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 10 — https://www.sorainen.com/lt/naujienos

Run: 2026-08-11T07:03:34.119Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 22614 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 78 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.8 s** / 1389 ms p75 (fast) | 1.1 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.004** / 0 p75 (fast) |
| TBT | **530 ms** | 368 ms |
| FCP | **3.07 s** / 1134 ms p75 (fast) | 871 ms / 924 ms p75 (fast) |
| Speed Index | **5.00 s** | 1.69 s |
| TTFB | 3 ms / 690 ms p75 (fast) | **11 ms** / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.8 s
2. **total-blocking-time** (medium) — 530 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 5.0 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://connect.facebook.net/en_US/fbevents.js — 171 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 170 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 148 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 132 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 112 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 93 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 90 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 87 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 75 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 67 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.30, weight 25) — Largest Contentful Paint — 4.8 s
- `total-blocking-time` (performance, score 0.55, weight 30) — Total Blocking Time — 530 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.63, weight 10) — Speed Index — 5.0 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.1 s
- `max-potential-fid` (performance, score 0.77, weight 0) — Max Potential First Input Delay — 170 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 409 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lt/naujienos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:30:38 GMT
- expires: Tue, 11 Aug 2026 07:03:34 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 20095
- Decoded body: 81.0 KB
- Compression ratio: 0.242

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 20095
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:03:34 GMT
expires: Tue, 11 Aug 2026 07:03:34 GMT
keep-alive: timeout=5, max=99
last-modified: Mon, 10 Aug 2026 16:30:38 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1132 ms._

**Scoring:** 12 errors · 17 warnings · 76 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 350
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 348
3. **Duplicate ID “select-finansai-ir-draudimas”.** (medium) — x1, first at line 350
4. **Duplicate ID “select-draudimas”.** (medium) — x1, first at line 350
5. **Duplicate ID “select-kapitalo-rinkos”.** (medium) — x1, first at line 350

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 91 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 348 `<a href="https://www.sorainen.com/lt/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 350 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-finansai-ir-draudimas”. — first at line 350 `a</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [warning] The first occurrence of ID “select-finansai-ir-draudimas” was here. — first at line 350 `s</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [error] Duplicate ID “select-draudimas”. — first at line 350 `s</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [warning] The first occurrence of ID “select-draudimas” was here. — first at line 350 `ė</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [error] Duplicate ID “select-kapitalo-rinkos”. — first at line 350 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [warning] The first occurrence of ID “select-kapitalo-rinkos” was here. — first at line 350 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas-ir-statyba”. — first at line 350 `i</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas-ir-statyba” was here. — first at line 350 `a</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas”. — first at line 350 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas” was here. — first at line 350 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [error] Duplicate ID “select-statyba”. — first at line 350 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [warning] The first occurrence of ID “select-statyba” was here. — first at line 350 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 450 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 455 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 259 `<h2 class="postsEmpty__title">Nėra r`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3503 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-115923 > a`
- `#menu-item-5498 > a`
- `a[aria-current="page"]`
- `#menu-item-115926 > a`
- `#menu-item-5501 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3519 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 67 network requests · 17.42 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 28 | 1.22 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.6 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 798 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 510 ms, 137.9 KB
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 448 ms, 331.9 KB
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lt&order=DESC&orderby=date&currentPage=2 (xhr) — 443 ms, 3.1 KB
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/feedback/schema (fetch) — 373 ms, 752 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/refill (fetch) — 352 ms, 2 B

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431814569&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=948523382&_eu=AAAAAGAC&are=1&cid=281123965.1786431815&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118897920~118897930~119367802~119367810~119404703~119527019~119896803~120125305~120315583~120385422&sid=1786431815&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1063 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431814569&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=948523382&_eu=AAAAAGAC&are=1&cid=281123965.1786431815&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118897920~118897930~119367802~119367810~119404703~119527019~119896803~120125305~120315583~120385422&sid=1786431815&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1063 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=adfr181hgicu)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=adfr181hgicu)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3519 ms._

**Document:**
- Lang: lt-LT
- Title: Naujienos - Sorainen
- Canonical: https://www.sorainen.com/lt/naujienos/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 135568

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nėra rezultatų
  - h3: Privatiems klientams padedame apsaugoti, auginti ir perduoti turtą ateities kart
  - h3: Mokesčių naujienos: 2026 m. antrasis ketvirtis
  - h3: „Sorainen“ paskelbė 2026 m. tvarumo ataskaitą: atsakingas augimas per kryptingą 
  - h3: „Sorainen“ jau rekordinį dešimtą kartą pripažinta IFLR Baltijos metų teisės firm
  - h3: „Sorainen“ pripažinta Baltijos šalių metų teisės firma „Chambers Europe“ 2026 m.
  - h3: Stipriname ginčų ir ESG kompetencijas: prie komandos jungiasi advokatė Renata Ja
  - h3: 2026 metų Baltijos sandoriai: „Salling Group“, „Tele2“ / „Manulife“, „nexos.ai“,
  - h3: „Sorainen“ reikšmingai stiprina savo komandą: daugiausiai partnerių ir stipriaus
  - h3: „Sorainen“ paskyrė tris naujus partnerius
  - h3: Mūsų komanda pelnė pirmas pozicijas „Chambers FinTech 2026“ reitinguose visose B
  - h3: Užsisakykite mūsų naujienlaiškį!
  - h3: Ieškoti naujienų
  - h3: Raktiniai žodžiai
  - h3: Sektorius
  - h3: Paslauga
  - h3: Šalis
  - h3: Data
  - h3: Data
  - h4: Domina aktualios verslo teisės naujienos?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 53 total — 1 defer, 7 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 6 inline (26.6 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 88 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "naujienos" ×3
- "saulė dagilytė" ×3
- "dr mindaugas lukas" ×3
- "sorainen" ×2
- "paslaugos" ×2
- "komanda" ×2
- "karjera" ×2
- "apie mus" ×2
- "kontaktai" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 6 of 10 — https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus

Run: 2026-08-11T07:03:56.734Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 19546 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 74 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.0 s** / 1389 ms p75 (fast) | 1.4 s / 1058 ms p75 (fast) |
| CLS | **0.004** / 0 p75 (fast) | 0.003 / 0 p75 (fast) |
| TBT | 112 ms | **445 ms** |
| FCP | **3.02 s** / 1134 ms p75 (fast) | 808 ms / 924 ms p75 (fast) |
| Speed Index | **3.84 s** | 1.57 s |
| TTFB | 3 ms / 690 ms p75 (fast) | 3 ms / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 11.0 s
2. **first-contentful-paint** (high) — 3.0 s
3. **speed-index** (low) — 3.8 s
4. **cache-insight** (high) — Est savings of 99 KiB
5. **document-latency-insight** (high) — Est savings of 460 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871h1 — 70 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.004

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871h1 — 92 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 86 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 83 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 78 ms
- https://connect.facebook.net/en_US/fbevents.js — 71 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.0 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.49, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.83, weight 10) — Speed Index — 3.8 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 12.0 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 356 ms._

**Transport:**
- Final URL: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:30:44 GMT
- expires: Tue, 11 Aug 2026 07:03:57 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16549
- Decoded body: 64.1 KB
- Compression ratio: 0.252

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16549
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:03:57 GMT
expires: Tue, 11 Aug 2026 07:03:57 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 16:30:44 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1079 ms._

**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)

> **Validator truncated at line 306** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 306** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 284
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 297
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 306
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 306

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 284 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 297 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2958 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2971 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 62 network requests · 17.38 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.19 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 903 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 403 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 361 ms, 2 B
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus (document) — 330 ms, 0 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 243 ms, 137.9 KB
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 240 ms, 331.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431837150&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1995267747&_eu=AAAAAGAC&are=1&cid=1989905795.1786431838&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896803~120125304~120385422&sid=1786431837&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=841 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431837150&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1995267747&_eu=AAAAAGAC&are=1&cid=1989905795.1786431838&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=12&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896803~120125304~120385422&sid=1786431837&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=841 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=55063wiqo35a)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=55063wiqo35a)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2971 ms._

**Document:**
- Lang: en-US
- Title: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and Belarus - Sorainen
- Canonical: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106815

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and B
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 64 anchors — 16 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 7 of 10 — https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen

Run: 2026-08-11T07:04:16.281Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 20903 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **45** | 93 |
| Accessibility | 81 | 81 |
| Best Practices | **69** | 73 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **12.0 s** / 1389 ms p75 (fast) | 1.3 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | **471 ms** | 121 ms |
| FCP | **8.93 s** / 1134 ms p75 (fast) | 792 ms / 924 ms p75 (fast) |
| Speed Index | **8.93 s** | 1.22 s |
| TTFB | 3 ms / 690 ms p75 (fast) | **7 ms** / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 12.0 s
2. **total-blocking-time** (medium) — 470 ms
3. **first-contentful-paint** (high) — 8.9 s
4. **speed-index** (high) — 8.9 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 72 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 229 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 193 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 174 ms
- https://connect.facebook.net/en_US/fbevents.js — 167 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 130 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 114 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 109 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 100 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 73 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `httpsOk`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 12.0 s
- `total-blocking-time` (performance, score 0.61, weight 30) — Total Blocking Time — 470 ms
- `first-contentful-paint` (performance, score 0.00, weight 10) — First Contentful Paint — 8.9 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `speed-index` (performance, score 0.15, weight 10) — Speed Index — 8.9 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `is-on-https` (best-practices, score 0.00, weight 5) — Does not use HTTPS — 1 insecure request found
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `lcp-breakdown-insight` (performance, score 0.00, weight 0) — LCP breakdown
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.13, weight 0) — Time to Interactive — 12.9 s
- … and 1 more

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 464 ms._

**Transport:**
- Final URL: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:30:45 GMT
- expires: Tue, 11 Aug 2026 07:04:16 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16575
- Decoded body: 64.4 KB
- Compression ratio: 0.251

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16575
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:04:16 GMT
expires: Tue, 11 Aug 2026 07:04:16 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 16:30:45 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1154 ms._

**Scoring:** 5 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 298** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 298** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 276
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 289
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 298
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 298

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 276 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 289 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3082 ms._

**Scoring:** 7 violations · 47 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3101 ms._

**Capture summary:** 10 console events · 0 mixed-content requests · 63 network requests · 17.38 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.19 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 54.7 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen (document) — 443 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 410 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 341 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 264 ms, 137.9 KB
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 255 ms, 331.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431856809&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1506406687&_eu=AAAAAGAC&are=1&cid=1046055555.1786431857&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118012007~118897920~118897930~119367802~119367810~119527020~119896802&sid=1786431857&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=992 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431856809&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1506406687&_eu=AAAAAGAC&are=1&cid=1046055555.1786431857&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118012007~118897920~118897930~119367802~119367810~119527020~119896802&sid=1786431857&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=992 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3hwx79ho1axb)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3hwx79ho1axb)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3101 ms._

**Document:**
- Lang: en-US
- Title: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN - Sorainen
- Canonical: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 107098

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| /content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 58 anchors — 10 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: …nen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 8 of 10 — https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards

Run: 2026-08-11T07:04:37.184Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 75290 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 64 | 64 |
| Accessibility | 78 | 78 |
| Best Practices | **88** | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.0 s** / 1389 ms p75 (fast) | 1.0 s / 1058 ms p75 (fast) |
| CLS | 0.001 / 0 p75 (fast) | **0.002** / 0 p75 (fast) |
| TBT | 242 ms | **3.80 s** |
| FCP | **3.03 s** / 1134 ms p75 (fast) | 789 ms / 924 ms p75 (fast) |
| Speed Index | **3.65 s** | 2.22 s |
| TTFB | 2 ms / 690 ms p75 (fast) | **3 ms** / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 11.0 s
2. **first-contentful-paint** (high) — 3.0 s
3. **total-blocking-time** (low) — 240 ms
4. **speed-index** (low) — 3.6 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 72 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.001

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 152 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 116 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 93 ms
- https://connect.facebook.net/en_US/fbevents.js — 83 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 78 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 55 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 51 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 50 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.0 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `total-blocking-time` (performance, score 0.85, weight 30) — Total Blocking Time — 240 ms
- `speed-index` (performance, score 0.86, weight 10) — Speed Index — 3.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 12.0 s
- `max-potential-fid` (performance, score 0.83, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 345 ms._

**Transport:**
- Final URL: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:12:18 GMT
- expires: Tue, 11 Aug 2026 07:04:37 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 17564
- Decoded body: 67.4 KB
- Compression ratio: 0.255

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 17564
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:04:37 GMT
expires: Tue, 11 Aug 2026 07:04:37 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 16:12:18 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1135 ms._

**Scoring:** 20 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 311** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 311** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content.** (high) — x7, first at line 261
3. **Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.)** (high) — x5, first at line 261
4. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
5. **Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.)** (medium) — x2, first at line 262

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolin`
- (×5) [error] Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.) — first at line 261 `ar&rdquo;.<o_p></o_p>`
- (×7) [error] The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content. — first at line 261 `ar&rdquo;.<o_p></o_p>`
- (×2) [error] Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.) — first at line 262 `ed.&rdquo;<o_p></o_p>`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 289 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] End tag “a” violates nesting rules. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2975 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2987 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.39 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.19 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 55.6 KB |
| document | 3 | 17.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 417 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 352 ms, 2 B
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards (document) — 335 ms, 0 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 261 ms, 331.9 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 233 ms, 137.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431877604&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1778814179&_eu=AAAAAGAC&are=1&cid=1784303542.1786431878&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118897920~118897930~119367802~119367810~119527019~119896803~120125304&sid=1786431878&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=852 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431877604&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1778814179&_eu=AAAAAGAC&are=1&cid=1784303542.1786431878&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=15&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118897920~118897930~119367802~119367810~119527019~119896803~120125304&sid=1786431878&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=852 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=2uen08mz653n)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=2uen08mz653n)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2987 ms._

**Document:**
- Lang: en-US
- Title: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards - Sorainen
- Canonical: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 109750

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards
  - h2: More like this
  - h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
  - h3: Share your innovative ideas for improving the Estonian healthcare system
  - h3: Second time The Legal500 has recognised us as an ESG-focused firm in the Green G
  - h3: 2023: Year in review
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 61 anchors — 29 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 9 of 10 — https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year

Run: 2026-08-11T07:04:52.878Z

## Audit Coverage
**93%** of audit sources returned data.

Missing or failed sources:
- PageSpeed Insights (mobile): PSI HTTP 500

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 23984 ms (mobile + desktop in parallel)._
_Mobile strategy errored (PSI HTTP 500); desktop data duplicated for both._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 70 | 70 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | 0.9 s / 1058 ms p75 (fast) | 0.9 s / 1058 ms p75 (fast) |
| CLS | 0.002 / 0 p75 (fast) | 0.002 / 0 p75 (fast) |
| TBT | 692 ms | 692 ms |
| FCP | 852 ms / 924 ms p75 (fast) | 852 ms / 924 ms p75 (fast) |
| Speed Index | 1.80 s | 1.80 s |
| TTFB | 8 ms / 683 ms p75 (fast) | 8 ms / 683 ms p75 (fast) |
| INP (field only) | 45 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (high) — 690 ms
2. **speed-index** (medium) — 1.8 s
3. **cache-insight** (medium) — Est savings of 99 KiB
4. **document-latency-insight** (high) — Est savings of 450 ms
5. **font-display-insight** (high) — Est savings of 110 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted

#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.002
- article.postView > div.container > div.postContent > p — shift 0.000

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 182 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 175 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 160 ms
- https://connect.facebook.net/en_US/fbevents.js — 155 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 114 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 91 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 91 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 82 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 76 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 70 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.15, weight 30) — Total Blocking Time — 690 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `speed-index` (performance, score 0.71, weight 10) — Speed Index — 1.8 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `max-potential-fid` (performance, score 0.73, weight 0) — Max Potential First Input Delay — 180 ms
- `interactive` (performance, score 0.75, weight 0) — Time to Interactive — 3.3 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 442 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:13:02 GMT
- expires: Tue, 11 Aug 2026 07:04:53 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15994
- Decoded body: 63.6 KB
- Compression ratio: 0.245

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15994
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:04:53 GMT
expires: Tue, 11 Aug 2026 07:04:53 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 16:13:02 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1243 ms._

**Scoring:** 6 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 295** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 295** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
3. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 273
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 295
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 295

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 273 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3004 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3017 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.38 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.19 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 53.6 KB |
| document | 3 | 15.6 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year (document) — 434 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 434 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 392 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 264 ms, 331.9 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 251 ms, 137.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786431893390&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1316571765&_eu=AAAAAGAC&are=1&cid=239740195.1786431894&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119259606~119367802~119367810~119527020~119896803&sid=1786431893&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=962 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786431893390&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1316571765&_eu=AAAAAGAC&are=1&cid=239740195.1786431894&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119259606~119367802~119367810~119527020~119896803&sid=1786431893&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=962 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=38xjau9uwfbj)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=38xjau9uwfbj)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3017 ms._

**Document:**
- Lang: en-US
- Title: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyers as 'Bees of the Year' - Sorainen
- Canonical: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106398

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyer
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871h1 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ps://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 61 anchors — 12 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 10 of 10 — https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

Run: 2026-08-11T07:05:16.863Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 22337 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **47** | 68 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.8 s** / 1389 ms p75 (fast) | 2.1 s / 1058 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **888 ms** | 415 ms |
| FCP | **3.07 s** / 1134 ms p75 (fast) | 855 ms / 924 ms p75 (fast) |
| Speed Index | **4.43 s** | 1.73 s |
| TTFB | 3 ms / 690 ms p75 (fast) | **7 ms** / 683 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.8 s
2. **total-blocking-time** (high) — 890 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.4 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 220 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 200 ms
- https://connect.facebook.net/en_US/fbevents.js — 198 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 — 176 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 159 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 113 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 113 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 112 ms
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5 — 88 ms
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/ — 82 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.8 s
- `total-blocking-time` (performance, score 0.32, weight 30) — Total Blocking Time — 890 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.73, weight 10) — Speed Index — 4.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.13, weight 0) — Time to Interactive — 12.8 s
- `max-potential-fid` (performance, score 0.59, weight 0) — Max Potential First Input Delay — 220 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 545 ms._

**Transport:**
- Final URL: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 10 Aug 2026 16:13:04 GMT
- expires: Tue, 11 Aug 2026 07:05:17 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15611
- Decoded body: 61.2 KB
- Compression ratio: 0.249

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15611
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Tue, 11 Aug 2026 07:05:17 GMT
expires: Tue, 11 Aug 2026 07:05:17 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 10 Aug 2026 16:13:04 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1187 ms._

**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)

> **Validator truncated at line 297** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 297** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 275
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 288
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 297
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 297

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 275 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 288 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2976 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2986 ms._

**Capture summary:** 9 console events · 0 mixed-content requests · 62 network requests · 17.38 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.19 MB |
| other | 1 | 331.9 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 15.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.01 MB
- https://www.googletagmanager.com — 2 requests, 326.0 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 427 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 395 ms, 2 B
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys (document) — 387 ms, 0 B
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (script) — 267 ms, 331.9 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 240 ms, 137.9 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431917332&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1347398819&_eu=AAAAAGAC&are=1&cid=639953897.1786431918&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&sid=1786431917&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=911 — net::ERR_ABORTED
3. **failed request** (medium) — image: https://www.googletagmanager.com/a?v=3&t=l&pid=2120590131&rv=6871&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&u=AAAAAIAKAAAAACAgAAAAAAAY&ut=Ag&h=Ag&gtm=45je6871v898627717za20gzb835828663zd835828663&ccid=98627717&cid=G-05KWKD0TXJ&l=L442.S29.B23.E304.I487.TC27.HTC0.F492.C10~gtm.init_consent.S1.V0.E25.TS5ogtdma.TI14.TE0~gtm.init.S0.V0.E23.TS5ogtautoevents.TI18.TE0.TS5ogtipmark.TI16.TE0.TS5ogt1pdatav2.TI17.TE0.TS5ccdgafirst.TI39.TE0.TS5setproductsettings.TI38.TE0.TS5ogtgooglesignals.TI37.TE0.TS5ccdgaregscope.TI36.TE0.TS5ccdaddecs.TI35.TE0.TS5ccdemdownload.TI34.TE0.TS5ccdemform.TI33.TE0.TS5ccdemoutboundclick.TI32.TE0.TS5ccdempageview.TI31.TE0.TS5ccdemscroll.TI30.TE0.TS5ccdemsitesearch.TI29.TE0.TS5ccdemvideo.TI28.TE0.TS5ogteventcreate.TI26.TE0.TS5ogteventcreate.TI25.TE0.TS5ccdadd1pdata.TI23.TE0.TS5ccdadd1pdata.TI22.TE0.TS5ccdautoredact.TI21.TE0.TS5ccdgaadslink.TI20.TE0.TS5ogtgasend.TI12.TE21.TS5ccdconversionmarking.TI27.TE17.TS5ogteventcreate.TI24.TE17.TS5ccdgalast.TI19.TE17~*.S0.V0.E16~gtm.js.E17.TS5gct.TI10.TE0~*.S0.E2~gtm.dom.E2~gtm.load.S0.V0.E0~GA469 — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/a?v=3&t=l&pid=2120590131&rv=6871&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&u=AAAAAIAKAAAAACAgAAAAAAAY&ut=Ag&h=Ag&gtm=45je6871v898627717za20gzb835828663zd835828663&ccid=98627717&cid=G-05KWKD0TXJ&l=L442.S29.B23.E304.I487.TC27.HTC0.F492.C10~gtm.init_consent.S1.V0.E25.TS5ogtdma.TI14.TE0~gtm.init.S0.V0.E23.TS5ogtautoevents.TI18.TE0.TS5ogtipmark.TI16.TE0.TS5ogt1pdatav2.TI17.TE0.TS5ccdgafirst.TI39.TE0.TS5s...ad.TI34.TE0.TS5ccdemform.TI33.TE0.TS5ccdemoutboundclick.TI32.TE0.TS5ccdempageview.TI31.TE0.TS5ccdemscroll.TI30.TE0.TS5ccdemsitesearch.TI29.TE0.TS5ccdemvideo.TI28.TE0.TS5ogteventcreate.TI26.TE0.TS5ogteventcreate.TI25.TE0.TS5ccdadd1pdata.TI23.TE0.TS5ccdadd1pdata.TI22.TE0.TS5ccdautoredact.TI21.TE0.TS5ccdgaadslink.TI20.TE0.TS5ogtgasend.TI12.TE21.TS5ccdconversionmarking.TI27.TE17.TS5ogteventcreate.TI24.TE17.TS5ccdgalast.TI19.TE17~*.S0.V0.E16~gtm.js.E17.TS5gct.TI10.TE0~*.S0.E2~gtm.dom.E2~gtm.load.S0.V0.E0~GA469' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je6871v898627717z8835828663za20gzb835828663zd835828663&_p=1786431917332&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1347398819&_eu=AAAAAGAC&are=1&cid=639953897.1786431918&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&sid=1786431917&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=911 — net::ERR_ABORTED
- image: https://www.googletagmanager.com/a?v=3&t=l&pid=2120590131&rv=6871&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&u=AAAAAIAKAAAAACAgAAAAAAAY&ut=Ag&h=Ag&gtm=45je6871v898627717za20gzb835828663zd835828663&ccid=98627717&cid=G-05KWKD0TXJ&l=L442.S29.B23.E304.I487.TC27.HTC0.F492.C10~gtm.init_consent.S1.V0.E25.TS5ogtdma.TI14.TE0~gtm.init.S0.V0.E23.TS5ogtautoevents.TI18.TE0.TS5ogtipmark.TI16.TE0.TS5ogt1pdatav2.TI17.TE0.TS5ccdgafirst.TI39.TE0.TS5setproductsettings.TI38.TE0.TS5ogtgooglesignals.TI37.TE0.TS5ccdgaregscope.TI36.TE0.TS5ccdaddecs.TI35.TE0.TS5ccdemdownload.TI34.TE0.TS5ccdemform.TI33.TE0.TS5ccdemoutboundclick.TI32.TE0.TS5ccdempageview.TI31.TE0.TS5ccdemscroll.TI30.TE0.TS5ccdemsitesearch.TI29.TE0.TS5ccdemvideo.TI28.TE0.TS5ogteventcreate.TI26.TE0.TS5ogteventcreate.TI25.TE0.TS5ccdadd1pdata.TI23.TE0.TS5ccdadd1pdata.TI22.TE0.TS5ccdautoredact.TI21.TE0.TS5ccdgaadslink.TI20.TE0.TS5ogtgasend.TI12.TE21.TS5ccdconversionmarking.TI27.TE17.TS5ogteventcreate.TI24.TE17.TS5ccdgalast.TI19.TE17~*.S0.V0.E16~gtm.js.E17.TS5gct.TI10.TE0~*.S0.E2~gtm.dom.E2~gtm.load.S0.V0.E0~GA469 — csp
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=tnqsjflyz2tc)
- [error] Loading the image 'https://www.googletagmanager.com/a?v=3&t=l&pid=2120590131&rv=6871&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527020~119896802~120125304~120315583&u=AAAAAIAKAAAAACAgAAAAAAAY&ut=Ag&h=Ag&gtm=45je6871v898627717za20gzb835828663zd835828663&ccid=98627717&cid=G-05KWKD0TXJ&l=L442.S29.B23.E304.I487.TC27.HTC0.F492.C10~gtm.init_consent.S1.V0.E25.TS5ogtdma.TI14.TE0~gtm.init.S0.V0.E23.TS5ogtautoevents.TI18.TE0.TS5ogtipmark.TI16.TE0.TS5ogt1pdatav2.TI17.TE0.TS5ccdgafirst.TI39.TE0.TS5s...ad.TI34.TE0.TS5ccdemform.TI33.TE0.TS5ccdemoutboundclick.TI32.TE0.TS5ccdempageview.TI31.TE0.TS5ccdemscroll.TI30.TE0.TS5ccdemsitesearch.TI29.TE0.TS5ccdemvideo.TI28.TE0.TS5ogteventcreate.TI26.TE0.TS5ogteventcreate.TI25.TE0.TS5ccdadd1pdata.TI23.TE0.TS5ccdadd1pdata.TI22.TE0.TS5ccdautoredact.TI21.TE0.TS5ccdgaadslink.TI20.TE0.TS5ogtgasend.TI12.TE21.TS5ccdconversionmarking.TI27.TE17.TS5ogteventcreate.TI24.TE17.TS5ccdgalast.TI19.TE17~*.S0.V0.E16~gtm.js.E17.TS5gct.TI10.TE0~*.S0.E2~gtm.dom.E2~gtm.load.S0.V0.E0~GA469' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=w_Yb7dGGXaKesJ7BMiqFJqBG&size=invisible&anchor-ms=20000&execute-ms=30000&cb=tnqsjflyz2tc)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2986 ms._

**Document:**
- Lang: en-US
- Title: Edvîns Draba joins the Latvian Association of Patent Attorneys - Sorainen
- Canonical: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 103973

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Edvîns Draba joins the Latvian Association of Patent Attorneys
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e6871 (async)
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 59 anchors — 11 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).