20260812T105051Z-267e
- Audited URL
- https://www.sorainen.com/
- Timestamp
- 2026-08-12T11:14:36.384Z
- Kind
- site
- Pages
- 10
Weighted audit summary
Site overall 53 is the mean of 10 pages. Scores range 42 (https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year) → 66 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile PSI performance is critically low at 48, driven by a catastrophic LCP of 11.7 s and 15.61 MB of media weight. Accessibility is compromised by 2 critical axe violations (image-alt, button-name) and 3 serious issues. Security headers score 40/100 with weak HSTS and CSP allowing unsafe-inline, which is elevated to Priority 1 due to the inferred user-generated content signal. W3C validation shows 6 errors including nesting violations and missing alt attributes. Desktop performance (77) is significantly better than mobile, but mobile-first indexing penalizes the overall score heavily.
Audit Report: Law firm Sorainen - helping clients succeed in business
Website: https://www.sorainen.com/
Date: 12.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high
Pages Audited (10 of 10):
- https://www.sorainen.com/
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys
Summary of results
Overall Score: 53 / 100
Status: 🟠 Poor
Site overall 53 is the mean of 10 pages. Scores range 42 (https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year) → 66 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile PSI performance is critically low at 48, driven by a catastrophic LCP of 11.7 s and 15.61 MB of media weight. Accessibility is compromised by 2 critical axe violations (image-alt, button-name) and 3 serious issues. Security headers score 40/100 with weak HSTS and CSP allowing unsafe-inline, which is elevated to Priority 1 due to the inferred user-generated content signal. W3C validation shows 6 errors including nesting violations and missing alt attributes. Desktop performance (77) is significantly better than mobile, but mobile-first indexing penalizes the overall score heavily.
Per-page scores
🟠 Poor · https://www.sorainen.com/
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 53 | 55 | 77 | 92 | 92 | 40 |
🟠 Poor · https://www.sorainen.com/newsroom
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 53 | 55 | 85 | 92 | 85 | 40 |
🟠 Poor · https://www.sorainen.com/et/uudised
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 58 | 58 | 85 | 92 | 92 | 40 |
🟡 Needs Improvement · https://www.sorainen.com/lv/zinas
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 66 | 72 | 85 | 92 | 92 | 40 |
🟠 Poor · https://www.sorainen.com/lt/naujienos
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 58 | 61 | 85 | 92 | 92 | 40 |
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 48 | 45 | 81 | 92 | 77 | 40 |
🟠 Poor · https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 48 | 56 | 81 | 69 | 77 | 40 |
🟠 Poor · https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 52 | 55 | 78 | 88 | 77 | 40 |
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 42 | 48 | 81 | 88 | 77 | 40 |
🟠 Poor · https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 48 | 55 | 81 | 92 | 77 | 40 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
Optimization Checklist
1 of 4 passing — 1 pass · 2 warn · 1 fail · 3 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | Warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | Warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Reduce page weight and optimize media Performance
- Impact: LCP, FCP, Total Page Weight
- Problem: Total page weight is 18.34 MB with 15.61 MB in media; LCP is 17.1s on mobile (vs 1.9s desktop).
- Solution:
- Compress video assets (splash.webm failed to load, likely oversized).
- Convert images to WebP/AVIF.
- Implement lazy loading for below-fold images (19 currently missing).
- Use
fetchpriority="low"for non-critical media.
1B. Add alt text to all images Accessibility
- Impact: WCAG 1.1.1, SEO
- Problem: 12 images missing
altattribute (W3C errors + axe critical violations). - Solution:
- Audit all
<img>tags. - Add descriptive
alttext for content images. - Use
alt=""for decorative images (e.g., lines, icons).
- Audit all
1C. Harden Content Security Policy (CSP) Security
- Impact: XSS Protection
- Problem: CSP allows
unsafe-inlineandunsafe-evaldespite UGC signal (anchor href contains 'post'). - Solution:
- Remove
'unsafe-inline'and'unsafe-eval'fromscript-src. - Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).
- Ensure
connect-srcallows font checks (hello.myfonts.net currently blocked).
- Remove
1D. Reduce Page Weight & Optimize Video Performance
- Impact: LCP, FCP, Total Page Weight
- Problem: Mobile LCP is 11.6 s and total page weight is 17.42 MB, with a 15.61 MB video asset failing to load.
- Solution:
- Compress or lazy-load the splash video (currently 15.61 MB).
- Defer non-critical JavaScript (18 render-blocking scripts found).
- Implement responsive images to reduce payload on mobile.
1E. Fix Critical Form & Button Labels Accessibility
- Impact: WCAG 2.1.1, 4.1.2
- Problem: 3 critical axe violations: buttons lack discernible text, and form elements (search, newsletter) lack labels.
- Solution:
- Add
aria-labelto all icon buttons (e.g.,.search-submit). - Associate
<label>elements with all form inputs (e.g.,#search-text-1). - Ensure
<select>elements have visible labels.
- Add
1F. Harden CSP and HSTS Security
- Impact: XSS Defense, Transport Security
- Problem: CSP allows
unsafe-inlineandunsafe-evaldespite UGC signals; HSTS missingincludeSubDomainsandpreload. - Solution:
- Remove
'unsafe-inline'and'unsafe-eval'fromscript-srcin CSP. - Update HSTS header:
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload.
- Remove
1G. Fix critical form and button accessibility violations Accessibility
- Impact: WCAG 2.1 A/AA compliance, screen reader usability
- Problem: 3 critical axe violations: buttons lack discernible text, form elements (search, selects) lack labels, and select elements have no accessible names.
- Solution:
- Add
aria-labelor visible text to all buttons (e.g.,.search-submit). - Associate
<label>elements with all form inputs usingfor/id. - Ensure
<select>elements have visible labels oraria-label.
- Add
1H. Eliminate render-blocking JavaScript Performance
- Impact: FCP, TBT, LCP
- Problem: 18 render-blocking scripts in <head> (including jQuery, GTM, Facebook Pixel) delay FCP to 3.06 s and contribute to 992 ms TBT.
- Solution:
- Add
deferorasyncto non-critical scripts in<head>. - Move analytics and third-party tags (GTM, Facebook) to the footer or load via
requestIdleCallback. - Inline critical CSS and defer non-critical CSS.
- Add
1I. Eliminate render-blocking JavaScript to improve LCP Performance
- Impact: LCP, FCP, Speed Index
- Problem: LCP is 4.1 s on mobile; 18 render-blocking scripts identified including jQuery and analytics trackers.
- Solution:
Move non-critical scripts to footer or add
defer/asyncattributes. Prioritize deferringgtag.js,recaptcha, andfacebook_pixel.<script src="..." defer></script>
1J. Add a single H1 heading element SEO
- Impact: Document outline, Search ranking
- Problem: HTML Inventory shows 0 H1 elements; page starts with H2. This breaks document hierarchy.
- Solution:
Ensure the main page title is wrapped in
<h1>. Avoid multiple H1s.<h1>Ziņas</h1>
1K. Fix critical form and button accessibility issues Accessibility
- Impact: WCAG 2.1 A/AA compliance, Screen Reader usability
- Problem: 3 critical axe violations: buttons lack discernible text, form elements lack labels, and select elements lack accessible names.
- Solution:
- Add
aria-labelor visible text to all buttons (e.g.,.search-submit). - Associate
<label>elements with all form inputs (#search-text-1,#taxonomy-select-2). - Ensure all interactive elements have focusable, named targets.
- Add
1L. Reduce media weight and optimize LCP Performance
- Impact: LCP (10.9 s), Page Weight (17.39 MB), TBT (1.01 s)
- Problem: Browser runtime shows 15.61 MB of media (video) and LCP is 10.9 s on mobile; 16 render-blocking scripts contribute to TBT.
- Solution:
- Replace the 15.61 MB video with a lightweight poster image and lazy-load the video.
- Add
deferorasyncto the 16 render-blocking scripts in<head>. - Preload critical LCP image if it is an
<img>.
1M. Fix critical axe violations Accessibility
- Impact: WCAG 2.1 Level A (button-name, image-alt)
- Problem: axe-core found 2 critical violations: buttons without discernible text (
.search-submit) and images without alt attributes (.newsIntro__line--2). - Solution:
- Add
aria-labelor visible text to.search-submitbutton. - Add descriptive
alttext to all content images; usealt=""for decorative SVGs. - Ensure color contrast ratio is ≥4.5:1 for
.menu-itemlinks.
- Add
1N. Harden Content Security Policy Security
- Impact: XSS protection (CSP currently allows unsafe-inline/eval)
- Problem: CSP allows
'unsafe-inline'and'unsafe-eval', negating XSS protection; site signals indicate user-generated content exists. - Solution:
- Remove
'unsafe-inline'and'unsafe-eval'fromscript-src. - Implement nonce-based CSP:
script-src 'nonce-{random}' 'strict-dynamic'. - Whitelist only necessary third-party domains (e.g., Google Fonts, Analytics).
- Remove
1O. Fix critical axe-core violations Accessibility
- Impact: WCAG 2.1 AA Compliance
- Problem: 2 critical violations: buttons lack discernible text (
.search-submit), images lack alt text (.newsIntro__line--2). - Solution:
- Add
aria-labelor visible text to all buttons. - Ensure all
<img>tags have descriptivealtattributes. - Fix color contrast issues on menu links (serious violation).
- Add
1P. Harden Content Security Policy and HSTS Security
- Impact: XSS Protection, Transport Security
- Problem: CSP allows
unsafe-inlineandunsafe-eval(high risk for UGC site). HSTS missingincludeSubDomainsandpreload. - Solution:
- Remove
unsafe-inlineandunsafe-evalfrom CSP; use nonces/hashes for scripts. - Update HSTS:
max-age=31536000; includeSubDomains; preload. - Add
Referrer-Policy: strict-origin-when-cross-origin.
- Remove
1Q. Reduce media weight and fix failed video request Performance
- Impact: LCP, FCP, Total Page Weight
- Problem: Total page weight is 17.4 MB with 15.6 MB from media; LCP is 11.0 s on mobile. A video splash.webm request failed (ERR_ABORTED).
- Solution:
- Compress and convert video to modern formats (WebM/MP4) with lower bitrate.
- Implement lazy loading for non-critical media.
- Ensure the hero image is optimized (WebP/AVIF) and uses
fetchpriority="high". - Fix the broken video source path or remove the element if not essential.
1R. Reduce media weight and fix broken video Performance
- Impact: LCP, FCP, Page Weight
- Problem: Browser runtime shows 15.61 MB of media (15.61 MB total page weight), with a failed video request (splash.webm) and LCP at 11.7 s.
- Solution:
- Compress or lazy-load the hero video; consider using a poster image instead of autoplaying video.
- Convert large images to WebP/AVIF.
- Implement
fetchpriority="high"on the LCP image. - Fix the broken
splash.webmrequest or remove the reference.
1S. Fix critical image-alt and button-name violations Accessibility
- Impact: WCAG 2.1 A Compliance, Screen Reader Usability
- Problem: axe-core reports 2 critical violations: images missing
[alt]attributes and buttons (.search-submit,.col-tp-none) lacking discernible text. - Solution:
- Add descriptive
alttext to all content images; usealt=""for decorative SVGs. - Add
aria-labelor visible text to search and close buttons, e.g.,<button aria-label="Close">.
- Add descriptive
1T. Harden HSTS and CSP (UGC Signal) Security
- Impact: Transport Security, XSS Defense
- Problem: HSTS missing
includeSubDomains/preload; CSP allowsunsafe-inlineandunsafe-eval. UGC signal elevates XSS risk to Priority 1 per rubric. - Solution:
- Update HSTS:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload. - Remove
unsafe-inlineandunsafe-evalfrom CSPscript-src. Use nonces or hashes for inline scripts. - Add
Referrer-Policy: strict-origin-when-cross-origin.
- Update HSTS:
1U. Reduce media weight and fix LCP Performance
- Impact: LCP, FCP, Page Weight
- Problem: LCP is 11.0 s on mobile; total page weight is 17.39 MB with 15.61 MB in media (video splash.webm failed to load).
- Solution:
- Replace the 15.6 MB video splash with a lightweight poster image or compressed WebM.
- Implement lazy loading for off-screen media.
- Ensure the LCP element (likely hero image) is preloaded and sized correctly.
1V. Fix critical axe violations (buttons, images) Accessibility
- Impact: WCAG 2.1 A Compliance
- Problem: 2 critical violations:
button-name(search-submit, col-tp-none) andimage-alt(newsIntro__line--2). - Solution:
- Add
aria-labelor visible text to.search-submitand.col-tp-nonebuttons. - Add descriptive
alttext to.newsIntro__line--2image. - Ensure all decorative images use
alt="".
- Add
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Defer render-blocking scripts Performance
- Impact: FCP, TBT
- Problem: 11 render-blocking scripts detected; 4 in
<head>blocking rendering. - Solution:
- Add
deferorasyncto non-critical scripts (jQuery, GTM, Analytics). - Move scripts to footer where possible.
- Inline critical CSS and defer non-critical CSS.
- Add
2B. Complete HSTS configuration Security
- Impact: Transport Security
- Problem: HSTS present but missing
includeSubDomainsandpreloaddirectives. - Solution:
- Update header to:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload. - Submit domain to hstspreload.org after testing.
- Update header to:
2C. Resolve HTML Validation Errors Best Practices
- Impact: DOM Stability, SEO
- Problem: 10 W3C errors including duplicate IDs (e.g.,
select-50-8002b801-adc4a003) and invalid attributes (stylr,pause). - Solution:
- Ensure all
idattributes are unique across the document. - Remove invalid attributes like
stylron<a>andpauseon<video>. - Add missing spaces between attributes.
- Ensure all
2D. Optimize media assets and video loading Performance
- Impact: Page weight, LCP, bandwidth
- Problem: Total page weight is 17.4 MB, with media consuming 15.6 MB. A video resource failed to load (
splash.webm), and images lack dimensions. - Solution:
- Compress video or use adaptive streaming (HLS/DASH) instead of direct
.webm. - Add
widthandheightattributes to all images to prevent layout shifts. - Implement lazy loading for off-screen media.
- Compress video or use adaptive streaming (HLS/DASH) instead of direct
2E. Fix heading hierarchy and landmarks Accessibility
- Impact: Screen reader navigation, SEO structure
- Problem: Document has 0
<h1>elements, missing<main>landmark, and no skip-to-content link. - Solution:
- Add a single
<h1>at the top of the content (e.g., 'Uudised'). - Wrap main content in
<main>tag. - Add a skip-link anchor at the top of the
<body>.
- Add a single
2F. Strengthen HSTS and add missing headers Security
- Impact: Transport security, clickjacking protection
- Problem: HSTS is missing
includeSubDomainsandpreload. Referrer-Policy and Permissions-Policy are absent. - Solution:
- Update HSTS to:
max-age=63072000; includeSubDomains; preload. - Add
Referrer-Policy: strict-origin-when-cross-origin. - Add
Permissions-Policyto disable unused features (e.g., geolocation, camera).
- Update HSTS to:
2G. Strengthen HSTS and resolve CSP blocking errors Security
- Impact: Transport security, Resource loading stability
- Problem: HSTS missing
includeSubDomains; CSP blockshello.myfonts.netcausing console errors and potential font load failures. - Solution:
Update HSTS header:
Update CSPStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadconnect-srcto allowhello.myfonts.netif required, or remove the script causing the violation.
2H. Defer unused third-party JavaScript Performance
- Impact: TBT, Page Weight
- Problem: 164 KB wasted on recaptcha, 71 KB on gtag; long tasks detected from these scripts.
- Solution:
Load analytics and marketing scripts only after user interaction or via
defer. Consider removing unused tracking pixels.
2I. Fix CSP blocking and harden HSTS Security
- Impact: Resource loading, Transport security
- Problem: CSP blocks
hello.myfonts.netcausing console errors; HSTS missingincludeSubDomainsandpreload. - Solution:
- Update CSP
connect-srcto allowhttps://hello.myfonts.net. - Update HSTS header:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload. - Remove
unsafe-inlinefrom CSPscript-srcif possible, or use nonces.
- Update CSP
2J. Fix HTML validation and meta tags SEO
- Impact: Search indexing, crawlability
- Problem: W3C reports 5 errors (nesting, illegal href characters); HTML Inventory shows missing meta description.
- Solution:
- Add
<meta name="description" content="...">summarizing the article. - Fix
<a>hrefs to remove spaces (encode as%20). - Close
<a>tags properly to fix nesting errors.
- Add
2K. Add meta description and fix HTML validation SEO
- Impact: Search Snippets, Crawlability
- Problem: Meta description is missing. W3C validator reports 5 errors including bad href characters and nesting violations.
- Solution:
- Add a unique
<meta name="description">tag (150-160 chars). - Fix W3C errors: remove spaces in URL query strings, close
<a>tags properly. - Ensure
langattribute is set correctly on<html>.
- Add a unique
2L. Defer render-blocking JavaScript Performance
- Impact: FCP, TBT, Time to Interactive
- Problem: 16 render-blocking scripts detected in HTML inventory; 4 in <head> per checklist. TBT is 504 ms.
- Solution:
- Add
deferorasyncattributes to non-critical scripts (analytics, widgets). - Move script tags to the end of
<body>where possible. - Inline critical CSS and defer non-critical stylesheets.
- Add
2M. Harden Security Headers (HSTS & CSP) Security
- Impact: Transport Security, XSS Defense
- Problem: HSTS missing
includeSubDomainsandpreload. CSP allowsunsafe-inlineandunsafe-eval, negating XSS protection. - Solution:
- Update HSTS:
max-age=31536000; includeSubDomains; preload. - Refine CSP: Remove
unsafe-inlineandunsafe-evalfromscript-src. Use nonces or hashes for allowed scripts. - Add
Referrer-Policy: strict-origin-when-cross-origin.
- Update HSTS:
2N. Resolve W3C HTML Validation Errors Best Practices
- Impact: Render Consistency, SEO
- Problem: 20 validation errors including unknown element
o_p(x7) and missingaltattributes. Parser recovery failed at line 311. - Solution:
- Identify and remove the plugin/theme generating the invalid
<o_p>element. - Fix nesting errors (e.g.,
<a>inside<a>). - Ensure all
<img>tags havealtattributes.
- Identify and remove the plugin/theme generating the invalid
2O. Add meta description and fix W3C errors SEO
- Impact: Search Snippets, HTML Validity
- Problem: Missing meta description; W3C reports 6 errors including illegal href characters and nesting violations.
- Solution:
- Add
<meta name="description" content="...">summarizing the article. - Fix W3C errors: ensure
<a>tags are not nested, fix illegal characters inhref(spaces), and ensure proper nesting of<img>inside<a>.
- Add
2P. Harden HSTS and CSP headers Security
- Impact: Transport Security, XSS Defense
- Problem: HSTS missing
includeSubDomainsandpreload; CSP allowsunsafe-inlineandunsafe-eval(Grade 40/100). - Solution:
- Update HSTS:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload - Tighten CSP: Remove
unsafe-inlineandunsafe-eval; use nonces/hashes for scripts. - Add
Referrer-Policy: strict-origin-when-cross-origin.
- Update HSTS:
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Fix HTML nesting and validation errors Best Practices
- Impact: Maintainability, SEO
- Problem: W3C reports 15 errors including 'Start tag seen but element already open' and 'End tag violates nesting rules'.
- Solution:
- Fix anchor nesting (e.g.,
<a>inside<a>). - Ensure proper heading hierarchy (no empty
<h2>). - Validate HTML after script changes.
- Fix anchor nesting (e.g.,
3B. Add Meta Description SEO
- Impact: Search Snippets, CTR
- Problem: SEO audit failed
metaDescription; document lacks a summary for search engines. - Solution:
- Add a
<meta name="description" content="...">tag with 150–160 characters summarizing the newsroom content.
- Add a
3C. Add meta description and fix HTML errors SEO
- Impact: Search snippet quality, validation
- Problem: Meta description is missing. W3C validator reports 8 errors (duplicate IDs, bad attributes, no space between attributes).
- Solution:
- Write a unique meta description (150–160 chars).
- Fix duplicate ID
select-kapitaliturud. - Correct malformed attributes (e.g.,
stylr→style,pauseon video).
3D. Harden Content Security Policy (CSP) Security
- Impact: XSS defense-in-depth
- Problem: CSP allows
unsafe-inlineandunsafe-eval, reducing XSS protection. Site signals show no auth/payments, so this is lower priority. - Solution:
Replace
unsafe-inlinewith nonces or hashes for scripts/styles. Removeunsafe-evalwhere possible.
3E. Fix HTML validation errors (Duplicate IDs) Best Practices
- Impact: Maintainability, DOM stability
- Problem: W3C reports 11 errors including duplicate IDs (e.g.,
select-50-8002b801-ae3c5c07) and attribute syntax issues. - Solution:
Ensure all
idattributes are unique within the document. Fix attribute spacing syntax (e.g.,value="" placeholder="").
3F. Fix HTML structure and validation errors SEO
- Impact: Document outline, Search indexing
- Problem: 12 W3C errors including missing H1, duplicate IDs, and invalid attributes (
stylr,pauseon video). - Solution:
- Add exactly one
<h1>element describing the page topic. - Ensure unique IDs for all elements (fix
select-finansai-ir-draudimasduplicates). - Remove invalid attributes and fix
</p>tag nesting.
- Add exactly one
▸Raw Markdown sent to the LLM
# Site Audit — https://www.sorainen.com/
Run: 2026-08-12T11:00:00.060Z
Audited **10** of 10 discovered pages.
Average per-page audit coverage: **100%**
Pages audited:
- https://www.sorainen.com/
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys
---
# Page 1 of 10 — https://www.sorainen.com/
Run: 2026-08-12T11:00:04.679Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 25981 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **55** | 64 |
| Accessibility | 77 | 77 |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **17.1 s** / 1391 ms p75 (fast) | 1.9 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | 143 ms | **588 ms** |
| FCP | **8.88 s** / 1137 ms p75 (fast) | 601 ms / 917 ms p75 (fast) |
| Speed Index | **8.88 s** | 2.01 s |
| TTFB | 2 ms / 680 ms p75 (fast) | **3 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 17.1 s
2. **first-contentful-paint** (high) — 8.9 s
3. **speed-index** (high) — 8.9 s
4. **cache-insight** (high) — Est savings of 99 KiB
5. **font-display-insight** (high) — Est savings of 160 ms
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 73 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1754389560 — 38 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 209 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 167 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 ms
- https://connect.facebook.net/en_US/fbevents.js — 145 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 97 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 89 ms
- Unattributable — 79 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 77 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 75 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 55 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 17.1 s
- `first-contentful-paint` (performance, score 0.00, weight 10) — First Contentful Paint — 8.9 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `speed-index` (performance, score 0.15, weight 10) — Speed Index — 8.9 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.04, weight 0) — Time to Interactive — 17.7 s
- `max-potential-fid` (performance, score 0.78, weight 0) — Max Potential First Input Delay — 170 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 19 ms._
**Transport:**
- Final URL: https://www.sorainen.com/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 09:13:39 GMT
- expires: Wed, 12 Aug 2026 11:00:04 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 13893
- Decoded body: 59.1 KB
- Compression ratio: 0.229
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 13893
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:04 GMT
expires: Wed, 12 Aug 2026 11:00:04 GMT
keep-alive: timeout=5, max=95
last-modified: Wed, 12 Aug 2026 09:13:39 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 780 ms._
**Scoring:** 15 errors · 8 warnings · 34 cosmetic (suppressed)
> **Validator truncated at line 405** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 405** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (high) — x12, first at line 253
3. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 405
4. **End tag “a” violates nesting rules.** (medium) — x1, first at line 405
5. **Cannot recover after last error. Any further errors will be ignored.** (medium) — x1, first at line 405
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 5 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 101 `33;" />
<script type="text/javascript">
(f`
- (×12) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 253 `<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/img/line__ho`
- (×1) [warning] Empty heading. — first at line 281 `<h2></h2>`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 332 `<section class="homePeople bg-purple">
<d`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 405 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 405 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 405 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2663 ms._
**Scoring:** 7 violations · 46 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.headerSearch__toggle.col-tp-none.col-m-none`
- `.submit`
- `.close`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.homeHero__line1`
- `.homeHero__line2`
- `.line__homePeople_1`
- `.line__homePeople_2`
- `.line__homePeople_3`
- … and 3 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `h1`
- `.homeHero__line1`
- `.homeHero__quote`
- … and 16 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 2 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2679 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 69 network requests · 18.34 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 20 | 1.18 MB |
| image | 26 | 1.02 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 7 | 76.7 KB |
| document | 2 | 13.6 KB |
| fetch | 6 | 44 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 257 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 227 ms, 138.6 KB
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (script) — 167 ms, 862 B
- https://fonts.gstatic.com/s/roboto/v48/KFO7CnqEu92Fr1ME7kSn66aGLdTylUAMa3yUBA.woff2 (font) — 153 ms, 39.2 KB
- https://cdn-cookieyes.com/assets/images/poweredbtcky.svg (image) — 136 ms, 0 B
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532404838&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1880307200&_eu=AAAAAGAC&are=1&cid=352122321.1786532405&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=5&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786532405&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2F&dt=Law%20firm%20Sorainen%20-%20helping%20clients%20succeed%20in%20business&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=596 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532404838&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1880307200&_eu=AAAAAGAC&are=1&cid=352122321.1786532405&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=5&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786532405&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2F&dt=Law%20firm%20Sorainen%20-%20helping%20clients%20succeed%20in%20business&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=596 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=55z17i84idbv)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=55z17i84idbv)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2679 ms._
**Document:**
- Lang: en-US
- Title: Law firm Sorainen - helping clients succeed in business
- Canonical: https://www.sorainen.com/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 101438
**Meta tags:**
- Description: With 300+ lawyers and tax specialists, we are the only truly integrated law firm in the Baltics working for a single goal – helping clients succeed.
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 2
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×6, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: We help clients succeed in business
- h2: Browse selected Sorainen insights and get future updates in your inbox
- h2:
- h2: Sorainen awarded by IFLR for a record 10th time for work on market-shaping trans
- h2: We are expanding our tax practice
- h2: One of Estonia’s most recognised and experienced transaction advisers, Sven Papp
- h2: Expertise
- h3: Eva Berlaus, Managing Partner
- h3: Eva Berlaus, Managing Partner
- h2: Newsroom
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 37 total — 1 defer, 6 async, 11 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1754389560
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1754389560
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 3 external, 6 inline (26.6 KB)
**Images:** 21 total — **12 without alt**, **16 without width/height**, 19 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_2.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| nt/uploads/2026/07/newsletter-subscription-2026-mainpage.gif | _(empty)_ | 1142×1243 | _n/a_ | ✗ |
| oads/2026/07/sorainen-sustainability2026-banner1284x1398.jpg | _(empty)_ | 1284×1398 | _n/a_ | ✓ |
| .com/wp-content/uploads/2026/06/iflr-award-2026-visual-2.png | _(empty)_ | 1620×1620 | _n/a_ | ✓ |
| tent/uploads/2026/04/copy-of-social-media-1200x630-px-54.png | _(empty)_ | 1142×1243 | lazy | ✓ |
| .com/wp-content/uploads/2026/04/sven-papp-web-front-page.png | Strengthening our corporate and M&A expe | 1142×1243 | lazy | ✓ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| /wp-content/themes/sorainen/build/img/line__homePeople_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/line__homePeople_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 78 anchors — 6 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "expertise" ×3
- "newsroom" ×3
- "sorainen" ×2
- "people" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "our expertise" ×2
- "show all news" ×2
- "kärt anna maire kelder" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- search — **no label**
### Priority fixes
1. **12 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **16 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **11 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 5 pass · 1 warn · 1 fail
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (16 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/5 raster images use srcset or <picture> (80%) (16 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 15 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
- `hero: …inen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-mainpage.gif`
- `loading: (not set)`
- `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
- `selector: div.expertiseIntro__img.bg-cover`
- `url: …sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-500x738.jpg`
- `box: 419×624px`
- Responsive images (srcset / <picture>):
- `…inen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-mainpage.gif`
- Reasonable number of image sizes:
- `widths: 46, 50, 150, 240, 310, 500, 541, 589, 768, 1142, 1284, 1320, 1440, 1536, 1620`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 2 of 10 — https://www.sorainen.com/newsroom
Run: 2026-08-12T11:00:04.681Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 23040 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **55** | 72 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 85 | 85 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.6 s** / 1391 ms p75 (fast) | 1.0 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | 474 ms | **507 ms** |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 817 ms / 917 ms p75 (fast) |
| Speed Index | **4.66 s** | 2.02 s |
| TTFB | 3 ms / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.6 s
2. **total-blocking-time** (medium) — 470 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.7 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 153 ms
- https://connect.facebook.net/en_US/fbevents.js — 139 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 139 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 133 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 89 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 82 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 78 ms
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 71 ms
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5 — 58 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.6 s
- `total-blocking-time` (performance, score 0.60, weight 30) — Total Blocking Time — 470 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.69, weight 10) — Speed Index — 4.7 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.0 s
- `max-potential-fid` (performance, score 0.80, weight 0) — Max Potential First Input Delay — 160 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 494 ms._
**Transport:**
- Final URL: https://www.sorainen.com/newsroom/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:00:38 GMT
- expires: Wed, 12 Aug 2026 11:00:05 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19207
- Decoded body: 79.7 KB
- Compression ratio: 0.235
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 19207
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:05 GMT
expires: Wed, 12 Aug 2026 11:00:05 GMT
keep-alive: timeout=5, max=94
last-modified: Tue, 11 Aug 2026 17:00:38 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1201 ms._
**Scoring:** 10 errors · 15 warnings · 76 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-adc4a003”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-insurance”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-50-8002b801-adc4a006”.** (medium) — x1, first at line 356
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/newsletter/" class="btn btn-primary btn-primar`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a003”. — first at line 356 `s</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a003” was here. — first at line 356 `g</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [error] Duplicate ID “select-insurance”. — first at line 356 `s</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [warning] The first occurrence of ID “select-insurance” was here. — first at line 356 `t</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a006”. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a006” was here. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c0d”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c0d” was here. — first at line 356 `n</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 452 `m>
</div>
</p>
<`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 457 `ide">
<video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">No res`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3413 ms._
**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3426 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 18.8 KB |
| xhr | 2 | 2.7 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.9 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=en&order=DESC&orderby=date¤tPage=2 (xhr) — 555 ms, 2.7 KB
- https://www.sorainen.com/newsroom (document) — 391 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 389 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 385 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 248 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532405200&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2042925834&_eu=AAAAAGAC&are=1&cid=946865796.1786532406&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119527019~119791749~119896803~120315583&sid=1786532405&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=962 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532405200&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2042925834&_eu=AAAAAGAC&are=1&cid=946865796.1786532406&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119527019~119791749~119896803~120315583&sid=1786532405&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=962 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=fzv4skojxv33)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=fzv4skojxv33)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3426 ms._
**Document:**
- Lang: en-US
- Title: Newsroom - Sorainen
- Canonical: https://www.sorainen.com/newsroom/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 133875
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: No results
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: Sorainen awarded IFLR Baltic Law Firm of the Year 2026 for record 10th time for
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h3: Sorainen awarded Baltic Law Firm of the Year at the Chambers Europe 2026 ceremon
- h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
- h3: We strengthen Dispute Resolution and ESG capabilities with the addition of attor
- h3: Baltic Deals of the Year 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
- h3: Join our newsletter!
- h3: Search news
- h3: Keyword
- h3: Sector
- h3: Service
- h3: Country
- h3: Date
- h3: Date
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 6 inline (26.6 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 93 anchors — 7 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×6
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "saulė dagilytė" ×2
- "laimonas skibarka" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 3 of 10 — https://www.sorainen.com/et/uudised
Run: 2026-08-12T11:00:27.721Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 831 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **58** | 97 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.8 s** / 1391 ms p75 (fast) | 0.9 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **992 ms** | 93 ms |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 789 ms / 917 ms p75 (fast) |
| Speed Index | **4.95 s** | 1.34 s |
| TTFB | 3 ms / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **total-blocking-time** (high) — 990 ms
2. **largest-contentful-paint** (medium) — 3.8 s
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 5.0 s
5. **cache-insight** (medium) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 70 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 249 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 204 ms
- https://connect.facebook.net/en_US/fbevents.js — 180 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 175 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 170 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 127 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 123 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 119 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 112 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 90 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.27, weight 30) — Total Blocking Time — 990 ms
- `largest-contentful-paint` (performance, score 0.54, weight 25) — Largest Contentful Paint — 3.8 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.64, weight 10) — Speed Index — 5.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.11, weight 0) — Time to Interactive — 13.5 s
- `max-potential-fid` (performance, score 0.50, weight 0) — Max Potential First Input Delay — 250 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 342 ms._
**Transport:**
- Final URL: https://www.sorainen.com/et/uudised/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 03:15:39 GMT
- expires: Wed, 12 Aug 2026 11:00:28 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 20201
- Decoded body: 82.2 KB
- Compression ratio: 0.24
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 20201
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:28 GMT
expires: Wed, 12 Aug 2026 11:00:28 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 12 Aug 2026 03:15:39 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1174 ms._
**Scoring:** 8 errors · 12 warnings · 79 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 359
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 54
3. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 357
4. **Duplicate ID “select-kapitaliturud”.** (medium) — x1, first at line 359
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 459
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 54 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 100 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 357 `<a href="https://www.sorainen.com/et/uudiskiri/" class="btn btn-primary btn-prim`
- (×3) [error] No space between attributes. — first at line 359 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-kapitaliturud”. — first at line 359 `)</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [warning] The first occurrence of ID “select-kapitaliturud” was here. — first at line 359 `s</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 459 `m>
</div>
</p>
<`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 464 `ide">
<video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 268 `<h2 class="postsEmpty__title">Tulemu`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3355 ms._
**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `#footer-menu > .current_page_parent.current_page_parent-type-post_type.current_page_parent-object-page > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3372 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.7 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=et&order=DESC&orderby=date¤tPage=2 (xhr) — 546 ms, 3.1 KB
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 366 ms, 2 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 364 ms, 668 B
- https://www.sorainen.com/et/uudised (document) — 336 ms, 0 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 228 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532428172&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2141556080&_eu=AAAAAGAC&are=1&cid=1188618192.1786532429&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118395333~118897920~118897930~119367802~119367810~119527020~119896803~120315584&sid=1786532428&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Uudised%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=868 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532428172&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=2141556080&_eu=AAAAAGAC&are=1&cid=1188618192.1786532429&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118395333~118897920~118897930~119367802~119367810~119527020~119896803~120315584&sid=1786532428&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Uudised%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=868 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=mt4dl6awvgd1)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=mt4dl6awvgd1)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3372 ms._
**Document:**
- Lang: et
- Title: Uudised - Sorainen
- Canonical: https://www.sorainen.com/et/uudised/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 136582
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Tulemusi ei leitud
- h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
- h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
- h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
- h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
- h3: Kohaliku omavalitsuse uudised: olulised muudatused ehituses, hariduses ja tarist
- h3: Sorainen valiti Chambers Europe 2026 galal Balti riikide aasta advokaadibürooks
- h3: Eduka Eesti võitis idee luua Eesti ettevõtete kaitseliit
- h3: 2026. aasta suurtehingud tegid Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
- h3: Maksu-uudised: vabatahtlik reserv omakapitali sissemaksena, Eesti maksutahtest j
- h3: Meie partneriteringiga on liitunud Eesti tuntumaid ja kogenumaid tehingunõustaja
- h3: Soovid meie uudiskirju?
- h3: Otsi uudiseid
- h3: Märksõna
- h3: Ärivaldkond
- h3: Õigusvaldkond
- h3: Riik
- h3: Kuupäev
- h3: Kuupäev
- h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 51 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 87 anchors — 8 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×4
- "uudised" ×3
- "kaupo lepasepp" ×3
- "sorainen" ×2
- "nõustamisvaldkonnad" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "iris magnus" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 4 of 10 — https://www.sorainen.com/lv/zinas
Run: 2026-08-12T11:00:30.661Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 21460 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **72** | 79 |
| Accessibility | 85 | **81** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** / 1391 ms p75 (fast) | 1.1 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | 326 ms | **391 ms** |
| FCP | **3.04 s** / 1137 ms p75 (fast) | 828 ms / 917 ms p75 (fast) |
| Speed Index | **4.26 s** | 1.45 s |
| TTFB | 12 ms / 680 ms p75 (fast) | **18 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **total-blocking-time** (low) — 330 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (low) — 4.3 s
5. **cache-insight** (medium) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 143 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 115 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 113 ms
- https://connect.facebook.net/en_US/fbevents.js — 110 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 103 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 71 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 69 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 64 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 56 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 56 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.46, weight 25) — Largest Contentful Paint — 4.1 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `total-blocking-time` (performance, score 0.76, weight 30) — Total Blocking Time — 330 ms
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.76, weight 10) — Speed Index — 4.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.13, weight 0) — Time to Interactive — 12.7 s
- `max-potential-fid` (performance, score 0.86, weight 0) — Max Potential First Input Delay — 140 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 441 ms._
**Transport:**
- Final URL: https://www.sorainen.com/lv/zinas/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 10:06:16 GMT
- expires: Wed, 12 Aug 2026 11:00:31 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19600
- Decoded body: 80.7 KB
- Compression ratio: 0.237
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19600
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:31 GMT
expires: Wed, 12 Aug 2026 11:00:31 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 12 Aug 2026 10:06:16 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 800 ms._
**Scoring:** 11 errors · 16 warnings · 83 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-ae3c5c07”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-finanses-un-apdrosinasana”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-kapitala-tirgi”.** (medium) — x1, first at line 356
### Issue groups
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/lv/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c07”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c07” was here. — first at line 356 `a</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [error] Duplicate ID “select-finanses-un-apdrosinasana”. — first at line 356 `a</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [warning] The first occurrence of ID “select-finanses-un-apdrosinasana” was here. — first at line 356 `i</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [error] Duplicate ID “select-kapitala-tirgi”. — first at line 356 `)</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [warning] The first occurrence of ID “select-kapitala-tirgi” was here. — first at line 356 `a</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [error] Duplicate ID “select-nekustamais-ipasums-un-buvnieciba”. — first at line 356 `a</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums-un-buvnieciba” was here. — first at line 356 `i</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [error] Duplicate ID “select-buvnieciba”. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [warning] The first occurrence of ID “select-buvnieciba” was here. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [error] Duplicate ID “select-nekustamais-ipasums”. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums” was here. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 455 `m>
</div>
</p>
<`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">Nekas`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3381 ms._
**Scoring:** 8 violations · 49 passes · critical 3 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5485 > a`
- `#menu-item-5486 > a`
- `#menu-item-115921 > a`
- `#footer-menu > .menu-item-104920.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5489 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3393 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 65 network requests · 1.81 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.1 KB |
| xhr | 2 | 3.0 KB |
| fetch | 8 | 809 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lv&order=DESC&orderby=date¤tPage=2 (xhr) — 497 ms, 3.0 KB
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/feedback/schema (fetch) — 403 ms, 763 B
- https://www.sorainen.com/lv/zinas (document) — 392 ms, 0 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/refill (fetch) — 388 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 240 ms, 335.7 KB
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532431120&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=662076792&_eu=AAAAAGAC&are=1&cid=753979570.1786532432&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119404702~119527019~119896803~120125305~120385423&sid=1786532431&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=886 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532431120&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=662076792&_eu=AAAAAGAC&are=1&cid=753979570.1786532432&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119404702~119527019~119896803~120125305~120385423&sid=1786532431&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=886 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ikfheab9pjzx)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ikfheab9pjzx)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3393 ms._
**Document:**
- Lang: lv-LV
- Title: Ziņas - Sorainen
- Canonical: https://www.sorainen.com/lv/zinas/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 133934
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Nekas netika atrasts
- h3: Palīdzam privātajiem klientiem aizsargāt un vairot kapitālu: Chambers reitingā S
- h3: Sorainen publicē Ilgtspējas ziņojumu 2026: atbildīga izaugsme un disciplinēts pr
- h3: iFinanses.lv: Kādos autopārvadājumos no 1. jūlija nepieciešams tahogrāfs?
- h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
- h3: Sorainen kļūst par “Liepāja 2027” juridisko partneri ceļā uz Eiropas kultūras ga
- h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
- h3: Sorainen ir atzīts par Gada advokātu biroju Baltijā Chambers Europe 2026 apbalvo
- h3: Sorainen kļūst par Latvijas E‑komercijas Asociācijas sadarbības partneri
- h3: Sorainen turpina atbalstīt Rīgas Juridiskās augstskolas bibliotēku
- h3: Baltijas gada darījumi 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCap
- h3: Piesakieties jaunumiem!
- h3: Meklēt ziņas
- h3: Atslēgvārds
- h3: Sektors
- h3: Pakalpojums
- h3: Valsts
- h3: Datums
- h3: Datums
- h4: Vai jūs interesē juridiskie jaunumi reģionā?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 73 anchors — 7 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×5
- "ziņas" ×3
- "sorainen" ×2
- "specializācija" ×2
- "komanda" ×2
- "karjera" ×2
- "par mums" ×2
- "kontakti" ×2
- "augustas klezys" ×2
- "piret jesse" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 5 of 10 — https://www.sorainen.com/lt/naujienos
Run: 2026-08-12T11:00:31.102Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 24379 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **61** | 81 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.0 s** / 1391 ms p75 (fast) | 1.2 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.004** / 0 p75 (fast) |
| TBT | **759 ms** | 327 ms |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 778 ms / 917 ms p75 (fast) |
| Speed Index | **4.83 s** | 1.45 s |
| TTFB | **3 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **total-blocking-time** (high) — 760 ms
2. **largest-contentful-paint** (medium) — 4.0 s
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.8 s
5. **cache-insight** (medium) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 202 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 184 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 180 ms
- https://connect.facebook.net/en_US/fbevents.js — 173 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 112 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 111 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 108 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 95 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 84 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 83 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.39, weight 30) — Total Blocking Time — 760 ms
- `largest-contentful-paint` (performance, score 0.51, weight 25) — Largest Contentful Paint — 4.0 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.66, weight 10) — Speed Index — 4.8 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.2 s
- `max-potential-fid` (performance, score 0.66, weight 0) — Max Potential First Input Delay — 200 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 408 ms._
**Transport:**
- Final URL: https://www.sorainen.com/lt/naujienos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:39 GMT
- expires: Wed, 12 Aug 2026 11:00:31 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19854
- Decoded body: 80.7 KB
- Compression ratio: 0.24
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 19854
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:31 GMT
expires: Wed, 12 Aug 2026 11:00:31 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 11 Aug 2026 17:19:39 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1135 ms._
**Scoring:** 12 errors · 17 warnings · 76 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-finansai-ir-draudimas”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-draudimas”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-kapitalo-rinkos”.** (medium) — x1, first at line 356
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/lt/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-finansai-ir-draudimas”. — first at line 356 `a</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [warning] The first occurrence of ID “select-finansai-ir-draudimas” was here. — first at line 356 `s</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [error] Duplicate ID “select-draudimas”. — first at line 356 `s</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [warning] The first occurrence of ID “select-draudimas” was here. — first at line 356 `ė</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [error] Duplicate ID “select-kapitalo-rinkos”. — first at line 356 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [warning] The first occurrence of ID “select-kapitalo-rinkos” was here. — first at line 356 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas-ir-statyba”. — first at line 356 `i</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas-ir-statyba” was here. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas”. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas” was here. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [error] Duplicate ID “select-statyba”. — first at line 356 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [warning] The first occurrence of ID “select-statyba” was here. — first at line 356 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 456 `m>
</div>
</p>
<`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 461 `ide">
<video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">Nėra r`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3466 ms._
**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-115923 > a`
- `#menu-item-5498 > a`
- `a[aria-current="page"]`
- `#menu-item-115926 > a`
- `#menu-item-5501 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3480 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.4 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 798 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lt&order=DESC&orderby=date¤tPage=2 (xhr) — 517 ms, 3.1 KB
- https://www.sorainen.com/lt/naujienos (document) — 394 ms, 0 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/feedback/schema (fetch) — 394 ms, 752 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/refill (fetch) — 348 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 233 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532431606&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1555511590&_eu=AAAAAGAC&are=1&cid=1491761460.1786532432&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=16&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786532432&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=929 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532431606&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1555511590&_eu=AAAAAGAC&are=1&cid=1491761460.1786532432&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=16&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119527020~119896803&sid=1786532432&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=929 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=8oy738rwndz)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=8oy738rwndz)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3480 ms._
**Document:**
- Lang: lt-LT
- Title: Naujienos - Sorainen
- Canonical: https://www.sorainen.com/lt/naujienos/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 135303
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Nėra rezultatų
- h3: Privatiems klientams padedame apsaugoti, auginti ir perduoti turtą ateities kart
- h3: Mokesčių naujienos: 2026 m. antrasis ketvirtis
- h3: „Sorainen“ paskelbė 2026 m. tvarumo ataskaitą: atsakingas augimas per kryptingą
- h3: „Sorainen“ jau rekordinį dešimtą kartą pripažinta IFLR Baltijos metų teisės firm
- h3: „Sorainen“ pripažinta Baltijos šalių metų teisės firma „Chambers Europe“ 2026 m.
- h3: Stipriname ginčų ir ESG kompetencijas: prie komandos jungiasi advokatė Renata Ja
- h3: 2026 metų Baltijos sandoriai: „Salling Group“, „Tele2“ / „Manulife“, „nexos.ai“,
- h3: „Sorainen“ reikšmingai stiprina savo komandą: daugiausiai partnerių ir stipriaus
- h3: „Sorainen“ paskyrė tris naujus partnerius
- h3: Mūsų komanda pelnė pirmas pozicijas „Chambers FinTech 2026“ reitinguose visose B
- h3: Užsisakykite mūsų naujienlaiškį!
- h3: Ieškoti naujienų
- h3: Raktiniai žodžiai
- h3: Sektorius
- h3: Paslauga
- h3: Šalis
- h3: Data
- h3: Data
- h4: Domina aktualios verslo teisės naujienos?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 51 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 6 inline (26.6 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 88 anchors — 7 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×5
- "naujienos" ×3
- "saulė dagilytė" ×3
- "dr mindaugas lukas" ×3
- "sorainen" ×2
- "paslaugos" ×2
- "komanda" ×2
- "karjera" ×2
- "apie mus" ×2
- "kontaktai" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 6 of 10 — https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus
Run: 2026-08-12T11:00:52.122Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 26456 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **45** | 81 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.9 s** / 1391 ms p75 (fast) | 1.9 s / 1059 ms p75 (fast) |
| CLS | **0.004** / 0 p75 (fast) | 0.003 / 0 p75 (fast) |
| TBT | **1.01 s** | 231 ms |
| FCP | **3.03 s** / 1137 ms p75 (fast) | 825 ms / 917 ms p75 (fast) |
| Speed Index | **4.52 s** | 1.66 s |
| TTFB | 3 ms / 680 ms p75 (fast) | **7 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 10.9 s
2. **total-blocking-time** (high) — 1,010 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (medium) — 4.5 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted
#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.004
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 241 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 240 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 212 ms
- https://connect.facebook.net/en_US/fbevents.js — 199 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 148 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 145 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 123 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 103 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 96 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 93 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.9 s
- `total-blocking-time` (performance, score 0.27, weight 30) — Total Blocking Time — 1,010 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.49, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.72, weight 10) — Speed Index — 4.5 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.14, weight 0) — Time to Interactive — 12.6 s
- `max-potential-fid` (performance, score 0.52, weight 0) — Max Potential First Input Delay — 240 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 330 ms._
**Transport:**
- Final URL: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:44 GMT
- expires: Wed, 12 Aug 2026 11:00:52 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 16547
- Decoded body: 64.1 KB
- Compression ratio: 0.252
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16547
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:52 GMT
expires: Wed, 12 Aug 2026 11:00:52 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:19:44 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1134 ms._
**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)
> **Validator truncated at line 306** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 306** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 284
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 297
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 306
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 306
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 284 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 297 `>
<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3069 ms._
**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3080 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 62 network requests · 17.39 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 438 ms, 663 B
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus (document) — 425 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 365 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 271 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 254 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532452647&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=211566043&_eu=AAAAAGAC&are=1&cid=1071219759.1786532453&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404700~119404703~119527019~119896802&sid=1786532453&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=977 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532452647&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=211566043&_eu=AAAAAGAC&are=1&cid=1071219759.1786532453&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404700~119404703~119527019~119896802&sid=1786532453&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=977 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=rp411q9fwa5n)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=rp411q9fwa5n)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3080 ms._
**Document:**
- Lang: en-US
- Title: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and Belarus - Sorainen
- Canonical: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106900
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and B
- h2: More like this
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 64 anchors — 16 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 7 of 10 — https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
Run: 2026-08-12T11:00:55.481Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 21340 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **56** | 71 |
| Accessibility | 81 | 81 |
| Best Practices | **69** | 73 |
| SEO | 77 | 77 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.0 s** / 1391 ms p75 (fast) | 0.9 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | 408 ms | **657 ms** |
| FCP | **3.10 s** / 1137 ms p75 (fast) | 793 ms / 917 ms p75 (fast) |
| Speed Index | **4.75 s** | 1.77 s |
| TTFB | 8 ms / 680 ms p75 (fast) | 8 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.0 s
2. **total-blocking-time** (medium) — 410 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.7 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 161 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 — 244 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 159 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 92 ms
- Unattributable — 90 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 89 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 87 ms
- https://connect.facebook.net/en_US/fbevents.js — 83 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 74 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 66 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 56 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `httpsOk`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.0 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `total-blocking-time` (performance, score 0.67, weight 30) — Total Blocking Time — 410 ms
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `is-on-https` (best-practices, score 0.00, weight 5) — Does not use HTTPS — 1 insecure request found
- `speed-index` (performance, score 0.68, weight 10) — Speed Index — 4.7 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.15, weight 0) — Time to Interactive — 12.2 s
- `max-potential-fid` (performance, score 0.51, weight 0) — Max Potential First Input Delay — 240 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 359 ms._
**Transport:**
- Final URL: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:46 GMT
- expires: Wed, 12 Aug 2026 11:00:55 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 16572
- Decoded body: 64.4 KB
- Compression ratio: 0.251
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16572
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:00:55 GMT
expires: Wed, 12 Aug 2026 11:00:55 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:19:46 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1172 ms._
**Scoring:** 5 errors · 6 warnings · 32 cosmetic (suppressed)
> **Validator truncated at line 298** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 298** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 276
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 289
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 298
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 298
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 276 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 289 `>
<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2932 ms._
**Scoring:** 7 violations · 47 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2942 ms._
**Capture summary:** 10 console events · 0 mixed-content requests · 63 network requests · 17.40 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 54.7 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 449 ms, 663 B
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen (document) — 381 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 348 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 258 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 237 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532455964&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=84244231&_eu=AAAAAGAC&are=1&cid=1171786489.1786532456&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119527019~119896803&sid=1786532456&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=912 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532455964&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=84244231&_eu=AAAAAGAC&are=1&cid=1171786489.1786532456&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=10&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119527019~119896803&sid=1786532456&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=912 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=o2b0pcl7h49b)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=o2b0pcl7h49b)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2942 ms._
**Document:**
- Lang: en-US
- Title: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN - Sorainen
- Canonical: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 107056
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN
- h2: More like this
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| /content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 58 anchors — 10 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
- `hero: …nen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg`
- `loading: (not set)`
- `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 8 of 10 — https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
Run: 2026-08-12T11:01:16.822Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 21227 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **55** | 85 |
| Accessibility | 78 | 78 |
| Best Practices | **88** | 92 |
| SEO | 77 | 77 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.0 s** / 1391 ms p75 (fast) | 1.6 s / 1059 ms p75 (fast) |
| CLS | 0.001 / 0 p75 (fast) | **0.005** / 0 p75 (fast) |
| TBT | **504 ms** | 142 ms |
| FCP | **3.10 s** / 1137 ms p75 (fast) | 791 ms / 917 ms p75 (fast) |
| Speed Index | **3.99 s** | 2.53 s |
| TTFB | **3 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.0 s
2. **total-blocking-time** (medium) — 500 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (low) — 4.0 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted
#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.001
#### Long tasks
- https://connect.facebook.net/en_US/fbevents.js — 166 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 166 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 155 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 110 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 93 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 89 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 84 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 75 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 63 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.0 s
- `total-blocking-time` (performance, score 0.58, weight 30) — Total Blocking Time — 500 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.81, weight 10) — Speed Index — 4.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.15, weight 0) — Time to Interactive — 12.4 s
- `max-potential-fid` (performance, score 0.78, weight 0) — Max Potential First Input Delay — 170 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 364 ms._
**Transport:**
- Final URL: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:51 GMT
- expires: Wed, 12 Aug 2026 11:01:17 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 17562
- Decoded body: 67.4 KB
- Compression ratio: 0.255
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 17562
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:01:17 GMT
expires: Wed, 12 Aug 2026 11:01:17 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:06:51 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1113 ms._
**Scoring:** 20 errors · 6 warnings · 32 cosmetic (suppressed)
> **Validator truncated at line 311** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 311** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content.** (high) — x7, first at line 261
3. **Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.)** (high) — x5, first at line 261
4. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
5. **Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.)** (medium) — x2, first at line 262
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
<script type="text/javascript">
(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolin`
- (×5) [error] Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.) — first at line 261 `ar”.<o_p></o_p>`
- (×7) [error] The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content. — first at line 261 `ar”.<o_p></o_p>`
- (×2) [error] Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.) — first at line 262 `ed.”<o_p></o_p>`
- (×1) [error] Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 289 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] End tag “a” violates nesting rules. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3250 ms._
**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3263 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.40 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 55.6 KB |
| document | 3 | 17.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards (document) — 464 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 448 ms, 663 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 392 ms, 335.7 KB
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 349 ms, 2 B
- https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532477390&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1634875967&_eu=AAAAAGAC&are=1&cid=26250462.1786532478&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527019~119896803~120125304~120385423&sid=1786532477&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1050 (fetch) — 303 ms, 0 B
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532477390&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1634875967&_eu=AAAAAGAC&are=1&cid=26250462.1786532478&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527019~119896803~120125304~120385423&sid=1786532477&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1050 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532477390&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1634875967&_eu=AAAAAGAC&are=1&cid=26250462.1786532478&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=0&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395334~118897920~118897930~119367802~119367810~119527019~119896803~120125304~120385423&sid=1786532477&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1050 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=o5254gx925vu)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=o5254gx925vu)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3263 ms._
**Document:**
- Lang: en-US
- Title: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards - Sorainen
- Canonical: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 109793
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards
- h2: More like this
- h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
- h3: Share your innovative ideas for improving the Estonian healthcare system
- h3: Second time The Legal500 has recognised us as an ESG-focused firm in the Green G
- h3: 2023: Year in review
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 61 anchors — 29 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
- `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG`
- `loading: (not set)`
- `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 9 of 10 — https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year
Run: 2026-08-12T11:01:18.578Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 19931 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **48** | 77 |
| Accessibility | 81 | 81 |
| Best Practices | **88** | 92 |
| SEO | 77 | 77 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.7 s** / 1391 ms p75 (fast) | 1.0 s / 1059 ms p75 (fast) |
| CLS | **0.036** / 0 p75 (fast) | 0.001 / 0 p75 (fast) |
| TBT | **832 ms** | 443 ms |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 848 ms / 917 ms p75 (fast) |
| Speed Index | **4.34 s** | 1.63 s |
| TTFB | **7 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.7 s
2. **total-blocking-time** (high) — 830 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (low) — 4.3 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
#### Layout-shift sources
- div#content > article.postView > div.container > div.postContent — shift 0.036
#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 240 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 — 200 ms
- https://connect.facebook.net/en_US/fbevents.js — 190 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 187 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 186 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 130 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 120 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 111 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 74 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 72 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.7 s
- `total-blocking-time` (performance, score 0.35, weight 30) — Total Blocking Time — 830 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.75, weight 10) — Speed Index — 4.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.13, weight 0) — Time to Interactive — 12.7 s
- `max-potential-fid` (performance, score 0.53, weight 0) — Max Potential First Input Delay — 240 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 331 ms._
**Transport:**
- Final URL: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:53 GMT
- expires: Wed, 12 Aug 2026 11:01:18 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 15992
- Decoded body: 63.6 KB
- Compression ratio: 0.245
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 15992
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:01:18 GMT
expires: Wed, 12 Aug 2026 11:01:18 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 11 Aug 2026 17:06:53 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1073 ms._
**Scoring:** 6 errors · 6 warnings · 32 cosmetic (suppressed)
> **Validator truncated at line 295** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 295** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
3. **Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 273
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 295
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 295
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
<script type="text/javascript">
(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.`
- (×1) [error] Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 273 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3023 ms._
**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3045 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.39 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 53.6 KB |
| document | 3 | 15.6 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.9 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 510 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 364 ms, 2 B
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year (document) — 339 ms, 0 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 292 ms, 138.6 KB
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 279 ms, 335.7 KB
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532479004&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=330292979&_eu=AAAAAGAC&are=1&cid=1127240737.1786532480&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=9&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118395335~118897920~118897930~119367802~119367810~119527019~119896802&sid=1786532479&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=917 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532479004&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=330292979&_eu=AAAAAGAC&are=1&cid=1127240737.1786532480&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=9&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118395335~118897920~118897930~119367802~119367810~119527019~119896802&sid=1786532479&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=917 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ii4x8xszyx)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ii4x8xszyx)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3045 ms._
**Document:**
- Lang: en-US
- Title: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyers as 'Bees of the Year' - Sorainen
- Canonical: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106396
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyer
- h2: More like this
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ps://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 61 anchors — 12 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
- `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg`
- `loading: (not set)`
- `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 10 of 10 — https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys
Run: 2026-08-12T11:01:38.049Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 20281 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **55** | 75 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.0 s** / 1391 ms p75 (fast) | 2.1 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **479 ms** | 296 ms |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 864 ms / 917 ms p75 (fast) |
| Speed Index | **4.38 s** | 1.61 s |
| TTFB | **8 ms** / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.0 s
2. **total-blocking-time** (medium) — 480 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.4 s
5. **cache-insight** (high) — Est savings of 99 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted
#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 216 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68b0h2 — 161 ms
- https://connect.facebook.net/en_US/fbevents.js — 152 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 150 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 111 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 85 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 84 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 77 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 60 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 55 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.0 s
- `total-blocking-time` (performance, score 0.60, weight 30) — Total Blocking Time — 480 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.74, weight 10) — Speed Index — 4.4 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.14, weight 0) — Time to Interactive — 12.5 s
- `max-potential-fid` (performance, score 0.61, weight 0) — Max Potential First Input Delay — 220 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 360 ms._
**Transport:**
- Final URL: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:55 GMT
- expires: Wed, 12 Aug 2026 11:01:38 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 15609
- Decoded body: 61.2 KB
- Compression ratio: 0.249
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15609
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:01:38 GMT
expires: Wed, 12 Aug 2026 11:01:38 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:06:55 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1143 ms._
**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)
> **Validator truncated at line 297** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 297** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 275
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 288
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 297
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 297
### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Bad value for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 275 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 288 `>
<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3212 ms._
**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes
#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3222 ms._
**Capture summary:** 9 console events · 0 mixed-content requests · 62 network requests · 17.39 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 15.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 456 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 439 ms, 138.6 KB
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys (document) — 435 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 375 ms, 2 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 374 ms, 663 B
### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — image: https://www.googletagmanager.com/td?id=G-05KWKD0TXJ&v=3&t=t&pid=1071447714>m=45je68a1v898627717za20gzb835828663zd835828663&seq=1&exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&dl=www.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&tdp=G-05KWKD0TXJ;98627717;1;6;0&frm=0&rtg=35828663&slo=19&hlo=15&lst=1&pcid=35828663&bt=0&ct=3&z=0 — csp
3. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532498588&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1535391018&_eu=AAAAAGAC&are=1&cid=1207529851.1786532499&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&sid=1786532499&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1206 — net::ERR_ABORTED
4. **console error** (medium) — Loading the image 'https://www.googletagmanager.com/td?id=G-05KWKD0TXJ&v=3&t=t&pid=1071447714>m=45je68a1v898627717za20gzb835828663zd835828663&seq=1&exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&dl=www.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&tdp=G-05KWKD0TXJ;98627717;1;6;0&frm=0&rtg=35828663&slo=19&hlo=15&lst=1&pcid=35828663&bt=0&ct=3&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked.
5. **console error** (medium) — requestStorageAccess: Permission denied.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- image: https://www.googletagmanager.com/td?id=G-05KWKD0TXJ&v=3&t=t&pid=1071447714>m=45je68a1v898627717za20gzb835828663zd835828663&seq=1&exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&dl=www.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&tdp=G-05KWKD0TXJ;98627717;1;6;0&frm=0&rtg=35828663&slo=19&hlo=15&lst=1&pcid=35828663&bt=0&ct=3&z=0 — csp
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532498588&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1535391018&_eu=AAAAAGAC&are=1&cid=1207529851.1786532499&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&sid=1786532499&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1206 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] Loading the image 'https://www.googletagmanager.com/td?id=G-05KWKD0TXJ&v=3&t=t&pid=1071447714>m=45je68a1v898627717za20gzb835828663zd835828663&seq=1&exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119404701~119527020~119896802&dl=www.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&tdp=G-05KWKD0TXJ;98627717;1;6;0&frm=0&rtg=35828663&slo=19&hlo=15&lst=1&pcid=35828663&bt=0&ct=3&z=0' violates the following Content Security Policy directive: "img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/". The action has been blocked. (https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/)
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=fryguorto02o)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=fryguorto02o)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3222 ms._
**Document:**
- Lang: en-US
- Title: Edvîns Draba joins the Latvian Association of Patent Attorneys - Sorainen
- Canonical: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 103951
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Edvîns Draba joins the Latvian Association of Patent Attorneys
- h2: More like this
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3
**Stylesheets:** 5 external, 5 inline (26.5 KB)
**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 59 anchors — 11 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).