Audit

20260812T110354Z-0e15

← Back to sorainencom
Audited URL
https://www.sorainen.com/et/
Timestamp
2026-08-12T11:22:51.665Z
Kind
site
Pages
10
Audit summary
https://www.sorainen.com/et/
10 of 10 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

54
Overall site quality
Poorhigh confidence

Site overall 54 is the mean of 10 pages. Scores range 38 (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen) → 68 (https://www.sorainen.com/et/uudised). Weakest page: Mobile performance is critically low (42/100) with an LCP of 9.3 s and 15.6 MB of media weight, dragging the score into the 'Poor' band. Accessibility is broken with 7 violations including 2 critical issues (missing alt text, button names) that block WCAG compliance. Security headers are weak (40/100) with a CSP allowing unsafe-inline, which is high risk given the inferred user-generated content signal. Desktop performance (97) contrasts sharply with mobile (42), indicating mobile-specific bottlenecks like render-blocking scripts and unoptimized media.

Per-page scores
58
/et
high
48
/newsroom
high
68
/et/uudised
high
58
/lv/zinas
high
58
/lt/naujienos
high
56
…the-baltics-and-belarus
high
38
…joins-law-firm-sorainen
high
52
…-lawyer-european-awards
high
48
…ers-as-bees-of-the-year
high
55
…ion-of-patent-attorneys
high

Audit Report: Advokaadibüroo Sorainen

Website: https://www.sorainen.com/et/
Date: 12.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high

Pages Audited (10 of 10):

Summary of results

Overall Score: 54 / 100
Status: 🟠 Poor

Site overall 54 is the mean of 10 pages. Scores range 38 (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen) → 68 (https://www.sorainen.com/et/uudised). Weakest page: Mobile performance is critically low (42/100) with an LCP of 9.3 s and 15.6 MB of media weight, dragging the score into the 'Poor' band. Accessibility is broken with 7 violations including 2 critical issues (missing alt text, button names) that block WCAG compliance. Security headers are weak (40/100) with a CSP allowing unsafe-inline, which is high risk given the inferred user-generated content signal. Desktop performance (97) contrasts sharply with mobile (42), indicating mobile-specific bottlenecks like render-blocking scripts and unoptimized media.

Per-page scores

🟠 Poor · https://www.sorainen.com/et

Score Performance Accessibility Best Practices SEO Security
58 57 77 92 92 40

🟠 Poor · https://www.sorainen.com/newsroom

Score Performance Accessibility Best Practices SEO Security
48 52 85 92 85 40

🟡 Needs Improvement · https://www.sorainen.com/et/uudised

Score Performance Accessibility Best Practices SEO Security
68 59 85 92 92 40

🟠 Poor · https://www.sorainen.com/lv/zinas

Score Performance Accessibility Best Practices SEO Security
58 60 85 92 92 40

🟠 Poor · https://www.sorainen.com/lt/naujienos

Score Performance Accessibility Best Practices SEO Security
58 65 85 92 92 40

🟠 Poor · https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus

Score Performance Accessibility Best Practices SEO Security
56 67 81 92 77 40

🟠 Poor · https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen

Score Performance Accessibility Best Practices SEO Security
38 42 81 69 77 40

🟠 Poor · https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards

Score Performance Accessibility Best Practices SEO Security
52 61 78 88 77 40

🟠 Poor · https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year

Score Performance Accessibility Best Practices SEO Security
48 46 81 88 77 40

🟠 Poor · https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

Score Performance Accessibility Best Practices SEO Security
55 53 81 92 77 40

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://www.sorainen.com/et 57 / 78 10.47 s / 1.96 s 0.000 / 0.007
https://www.sorainen.com/newsroom 52 / 82 11.56 s / 1.03 s 0.000 / 0.000
https://www.sorainen.com/et/uudised 59 / 68 4.88 s / 1.17 s 0.000 / 0.000
https://www.sorainen.com/lv/zinas 60 / 91 3.94 s / 1.07 s 0.000 / 0.001
https://www.sorainen.com/lt/naujienos 65 / 75 3.97 s / 1.03 s 0.000 / 0.004
https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus 67 / 98 12.06 s / 872 ms 0.004 / 0.003
https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen 42 / 97 9.31 s / 921 ms 0.000 / 0.001
https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards 61 / 60 12.15 s / 1.78 s 0.001 / 0.003
https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year 46 / 89 10.03 s / 1.19 s 0.036 / 0.002
https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys 53 / 58 10.93 s / 2.17 s 0.000 / 0.000

Optimization Checklist

1 of 4 passing — 1 pass · 2 warn · 1 fail · 3 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded N/A No raster <img> elements found (4 SVGs excluded).
Hero image eagerly loaded Warn Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Fail 4 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Reduce media weight and optimize LCP Performance

  • Impact: LCP, FCP, Page Weight
  • Problem: LCP is 10.5 s on mobile; total page weight is 18.45 MB with 15.61 MB in media (likely video).
  • Solution:
    • Replace the 15.6 MB video asset with a lightweight poster image or compressed WebM.
    • Implement lazy loading for all non-critical media.
    • Use fetchpriority="high" only on the actual LCP element.

1B. Add alt text to all images and label buttons Accessibility

  • Impact: WCAG 1.1.1, 4.1.2
  • Problem: 12 images lack alt attributes; 4 buttons (search, close) lack discernible text (axe critical violations).
  • Solution:
    • Add descriptive alt text to content images; use alt="" for decorative SVGs.
    • Add aria-label or visible text to .search-submit, .close, and .submit buttons.

1C. Harden Content Security Policy (CSP) Security

  • Impact: XSS Defense
  • Problem: CSP allows unsafe-inline and unsafe-eval scripts; UGC signal is yes, increasing XSS risk.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from script-src.
    • Implement nonce-based CSP for third-party scripts (GTM, Recaptcha).
    • Ensure connect-src allows font counting endpoints (hello.myfonts.net).

1D. Reduce Page Weight and Fix LCP Performance

  • Impact: LCP, FCP, Speed Index, Mobile Score
  • Problem: LCP is 11.6 s on mobile; total page weight is 17.42 MB (15.61 MB media). Video splash asset failed to load (ERR_ABORTED).
  • Solution:
    • Compress or lazy-load the hero video; ensure fallback image loads first.
    • Implement responsive images (srcset) for raster assets.
    • Preload critical LCP image if it is an <img>.
    • Audit third-party scripts (recaptcha, gtag) for necessity.

1E. Fix Critical Button and Label Violations Accessibility

  • Impact: WCAG 2.1 Level A Compliance
  • Problem: 3 critical axe violations: 5 buttons lack discernible text, search/select forms lack labels.
  • Solution:
    • Add aria-label or visible text to all buttons (e.g., .search-submit).
    • Associate <label> elements with all form inputs (for/id matching).
    • Ensure all interactive elements have accessible names.

1F. Add a Single H1 Element SEO

  • Impact: Document Outline, Search Ranking
  • Problem: HTML Inventory shows 0 h1 elements; page starts with h2. W3C warns no h1.
  • Solution:
    • Ensure exactly one <h1> exists per page, typically matching the <title> or main heading.
    • Example: <h1>Newsroom</h1> at the top of the main content area.

1G. Reduce LCP and render-blocking resources Performance

  • Impact: LCP, FCP, TBT
  • Problem: LCP is 4.9 s (threshold 2.5 s) with 15.6 MB media weight and 18 render-blocking scripts in the head.
  • Solution:
    • Optimize the 15.6 MB video asset (compress, use modern codecs, lazy load if not above fold).
    • Add defer or async to non-critical scripts (e.g., GTM, Facebook Pixel).
    • Inline critical CSS and move non-critical stylesheets to the footer.

1H. Fix critical form and button accessibility issues Accessibility

  • Impact: WCAG 2.1 A/AA compliance
  • Problem: 3 critical violations: buttons lack discernible text, search form lacks labels, select elements lack names.
  • Solution:
    • Add aria-label or visible text to all icon buttons (e.g., search submit).
    • Associate <label> elements with all form inputs using for and id.
    • Ensure all <select> elements have an associated label or aria-label.

1I. Defer non-critical JavaScript to reduce TBT Performance

  • Impact: TBT, FCP, LCP

  • Problem: TBT is 728 ms (>600 ms heavy penalty) and LCP is 3.9 s due to 18 render-blocking scripts and unused JS (recaptcha, gtag).

  • Solution: Add defer or async to non-critical scripts in <head>. Specifically target:

    • gtag.js
    • gtm.js
    • recaptcha__en.js
    • facebook_signal.js

    Example:

    <script src="/js/main.js" defer></script>
    

1J. Defer non-critical third-party scripts Performance

  • Impact: LCP, FCP, TBT (590 ms)
  • Problem: 18 render-blocking scripts and heavy JS (recaptcha, gtag, facebook-pixel) cause LCP 4.0 s and FCP 3.07 s on mobile.
  • Solution:
    • Move non-critical scripts to footer or add defer/async attributes.
    • Load recaptcha only on interaction (e.g., form focus).
    • Use preconnect for third-party domains (googleapis, gstatic).
    • Example: <script src="..." defer></script>

1K. Fix Largest Contentful Paint (LCP) of 12.1 s Performance

  • Impact: Core Web Vitals, Mobile Performance Score
  • Problem: LCP is 12.1 s on mobile (threshold is 2.5 s), caused by heavy media (15.6 MB video) and render-blocking resources.
  • Solution:
    • Preload the LCP image/video resource.
    • Convert video to adaptive streaming (HLS/DASH) or lazy-load below the fold.
    • Defer non-critical JavaScript to reduce main thread blocking.

1L. Resolve Critical Accessibility Violations Accessibility

  • Impact: WCAG Compliance, Screen Reader Usability
  • Problem: axe-core found 2 critical violations: buttons without discernible text (.search-submit) and images missing alt attributes (.newsIntro__line--2).
  • Solution:
    • Add aria-label or visible text to all buttons.
    • Ensure every <img> has a descriptive alt attribute.
    • Fix color contrast issues on menu links (#menu-item-5479 > a).

1M. Harden Content Security Policy (CSP) and HSTS Security

  • Impact: XSS Protection, Transport Security
  • Problem: CSP allows unsafe-inline and unsafe-eval (high risk for UGC sites); HSTS missing includeSubDomains and preload. Site signals indicate User-Generated Content.
  • Solution:
    • Remove unsafe-inline and unsafe-eval from CSP; use nonces/hashes for scripts.
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.

1N. Reduce media weight and fix LCP Performance

  • Impact: LCP, Page Weight, Mobile Performance
  • Problem: Mobile LCP is 9.3 s and total page weight is 17.4 MB (15.6 MB media), causing severe load delays on mobile networks.
  • Solution:
    • Compress or lazy-load the 15.6 MB media assets (likely video splash).
    • Use fetchpriority="high" on the LCP image.
    • Serve WebP/AVIF formats and implement responsive srcset.

1O. Fix critical axe-core violations Accessibility

  • Impact: WCAG 2.1 Compliance, Screen Reader Usability
  • Problem: 2 critical violations found: missing alt attributes on images and buttons without discernible text (.search-submit, .col-tp-none).
  • Solution:
    • Add descriptive alt text to all content images.
    • Add aria-label or visible text to icon buttons.
    • Ensure form inputs have associated <label> elements.

1P. Fix critical axe violations Accessibility

  • Impact: WCAG 2.1 A/AA Compliance
  • Problem: 2 critical violations: button-name (search-submit, col-tp-none) and image-alt (2 images missing alt).
  • Solution:
    • Add aria-label or visible text to .search-submit and .col-tp-none buttons.
    • Add descriptive alt text to all content images; use alt="" for decorative SVGs.
    • Ensure form inputs have associated <label> elements.

1Q. Harden CSP and HSTS headers Security

  • Impact: XSS Defense, Transport Security
  • Problem: CSP allows unsafe-inline and unsafe-eval (high risk with UGC signal); HSTS missing includeSubDomains and preload.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from CSP; use nonces/hashes for scripts.
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.
    • Add X-Content-Type-Options: nosniff (present) and Referrer-Policy: strict-origin-when-cross-origin.

1R. Reduce Largest Contentful Paint (LCP) from 10.0 s Performance

  • Impact: LCP, FCP, Mobile Performance Score
  • Problem: LCP is 10.0 s on mobile (target ≤2.5 s) due to 15.6 MB media weight and render-blocking scripts.
  • Solution:
    • Compress or lazy-load the 15.6 MB video asset; use a poster image for the hero.
    • Add fetchpriority="high" to the LCP image.
    • Defer non-critical JavaScript to reduce main thread blocking.

1S. Harden Content Security Policy (CSP) for User-Generated Content Security

  • Impact: XSS Protection, Security Headers Grade
  • Problem: CSP allows unsafe-inline and unsafe-eval, negating XSS protection. Site signals indicate user-generated content exists.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from script-src.
    • Implement nonce-based CSP for inline scripts.
    • Ensure connect-src allows only necessary third-party domains (currently blocking hello.myfonts.net).

1T. Fix Critical Axe Violations (Buttons & Images) Accessibility

  • Impact: WCAG 2.1 A Compliance, Screen Reader Support
  • Problem: 2 critical violations: buttons lack accessible names (.search-submit) and images lack alt attributes.
  • Solution:
    • Add aria-label or visible text to .search-submit button.
    • Add descriptive alt text to all content images; use alt="" for decorative SVGs.
    • Ensure form inputs have associated <label> elements.

1U. Reduce media asset weight (15.6 MB) Performance

  • Impact: LCP, FCP, Page Weight
  • Problem: Browser Runtime shows 15.61 MB of media (likely a background video) causing LCP to hit 10.9 s on mobile.
  • Solution: Replace the heavy video with a compressed WebM/MP4 (<5 MB) or a static poster image. If video is essential, use preload="none" and lazy-load it after interaction.

1V. Fix critical axe violations (buttons, images) Accessibility

  • Impact: WCAG 2.1 A Compliance
  • Problem: axe-core reports 2 critical violations: buttons lack discernible text (.search-submit) and images lack alt text (.newsIntro__line--2).
  • Solution:
    • Add aria-label or visible text to .search-submit.
    • Add descriptive alt text to all content images. Decorative images should use alt="".

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Defer render-blocking scripts Performance

  • Impact: FCP, TBT
  • Problem: 11 render-blocking scripts in <head> contribute to FCP 3.07 s and TBT 318 ms.
  • Solution:
    • Add defer or async to non-critical scripts (analytics, GTM, cookie consent).
    • Move jQuery and theme JS to the footer or load after LCP.

2B. Strengthen HSTS and add missing headers Security

  • Impact: Transport Security, Clickjacking
  • Problem: HSTS missing includeSubDomains and preload; Referrer-Policy and COOP missing.
  • Solution:
    • Update HSTS: max-age=31536000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.
    • Add Permissions-Policy to disable unused features.

2C. Defer Render-Blocking JavaScript Performance

  • Impact: TBT, FCP, Main Thread Blocking
  • Problem: 18 render-blocking scripts found; 4 in <head> flagged by checklist. TBT is 570 ms.
  • Solution:
    • Add defer or async to non-critical scripts.
    • Move analytics and tracking scripts to the footer.
    • Inline critical CSS and defer non-critical CSS.

2D. Harden CSP and complete security headers Security

  • Impact: XSS protection, transport security
  • Problem: CSP allows unsafe-inline and unsafe-eval; HSTS missing includeSubDomains and preload.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from CSP; use nonces for scripts.
    • Update HSTS to: max-age=31536000; includeSubDomains; preload.
    • Add Referrer-Policy: strict-origin-when-cross-origin.

2E. Add H1 and fix HTML validation errors SEO

  • Impact: Document outline, search ranking
  • Problem: Page has 0 <h1> elements and 8 W3C errors (duplicate IDs, bad attributes).
  • Solution:
    • Add a single <h1> describing the page content (e.g., 'Uudised').
    • Fix duplicate ID select-kapitaliturud.
    • Correct invalid attributes (e.g., stylr -> style, pause on video).

2F. Strengthen HSTS and fix CSP console errors Security

  • Impact: Transport security, XSS defense
  • Problem: HSTS missing includeSubDomains and preload; CSP blocks hello.myfonts.net causing console errors.
  • Solution:
    • Update HSTS header: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
    • Add https://hello.myfonts.net to connect-src in CSP if required, or remove the font counting script.

2G. Add H1 tag and main landmark SEO

  • Impact: SEO ranking, Screen Reader navigation
  • Problem: W3C reports 0 h1 elements; HTML Inventory shows missing <main> landmark.
  • Solution:
    • Ensure exactly one <h1> exists per page (e.g., <h1>Ziņas</h1>).
    • Wrap primary content in <main role="main">.
    • Add a skip-link at the top: <a href="#main" class="skip-link">Iet uz saturu</a>.

2H. Strengthen HSTS and baseline headers Security

  • Impact: Transport security, clickjacking protection
  • Problem: HSTS is missing includeSubDomains and preload directives; X-Frame-Options and X-Content-Type-Options are present but HSTS is weak.
  • Solution:
    • Update HSTS header: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    • Ensure X-Frame-Options: SAMEORIGIN remains active.
    • Remove Server header disclosure (Apache/ZoneOS).

2I. Eliminate Render-Blocking JavaScript Performance

  • Impact: FCP, TBT, Time to Interactive
  • Problem: 16 render-blocking scripts detected in <head>, including jQuery and analytics trackers, delaying first paint.
  • Solution:
    • Add defer or async to all non-critical scripts.
    • Move scripts to the end of <body> where possible.
    • Inline critical CSS and defer non-critical stylesheets.

2J. Complete HSTS configuration Security

  • Impact: Transport Security, Man-in-the-Middle Protection
  • Problem: HSTS header is present but missing includeSubDomains and preload directives, reducing protection scope.
  • Solution:
    • Update header to: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload.
    • Submit domain to hstspreload.org after testing.

2K. Fix HTML validation errors and meta data SEO

  • Impact: Search Indexing, Rendering Reliability
  • Problem: W3C reports 20 errors including unknown o_p elements and nesting issues; missing meta description.
  • Solution:
    • Remove or fix the o_p custom element (likely plugin artifact).
    • Add <meta name="description" content="...">.
    • Ensure <main> landmark exists and heading hierarchy is logical.

2L. Add Meta Description and Fix W3C Errors SEO

  • Impact: Search Snippets, HTML Validity
  • Problem: Missing meta description; 6 W3C errors including nesting violations and illegal characters in URLs.
  • Solution:
    • Add <meta name="description" content="..."> summarizing the article.
    • Fix <a> href spaces (encode as %20).
    • Close unclosed <a> tags to resolve nesting errors.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Fix HTML validation errors SEO

  • Impact: Crawlability, Rendering
  • Problem: W3C reports 16 errors including parser recovery failure at line 407 and empty href attributes.
  • Solution:
    • Fix nested <a> tags causing parser recovery failure.
    • Remove empty href attributes on <link> elements.
    • Ensure all <section> elements have headings.

3B. Resolve failed resource requests Performance

  • Impact: Page load stability
  • Problem: Console shows failed requests for splash.webm, recaptcha, and analytics.
  • Solution:
    • Verify splash.webm path and availability.
    • Ensure recaptcha keys are valid and not blocked by CSP.
    • Check analytics endpoints for CORS or network issues.

3C. Harden Content Security Policy (CSP) Security

  • Impact: XSS mitigation
  • Problem: CSP allows unsafe-inline and unsafe-eval, which bypasses XSS protection.
  • Solution: Since this is a brochure site (no auth/payments), prioritize P1/P2 first. When ready, migrate to nonce-based CSP:
    Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
    
    Remove unsafe-inline from script-src.

3D. Add Meta Description and Fix HTML Validation SEO

  • Impact: Search Snippets, Code Quality
  • Problem: Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.
  • Solution:
    • Add a unique <meta name="description"> tag (150–160 chars).
    • Fix W3C errors: remove spaces in query strings, ensure proper <a> nesting, and add missing alt attributes.

3E. Add meta description and fix HTML errors SEO

  • Impact: Search Snippets, Validation
  • Problem: Meta description is missing; W3C validator reports 5 errors including illegal characters in href and nesting violations.
  • Solution:
    • Write a unique meta description (150–160 chars) for the press release.
    • Fix W3C errors: remove spaces in query strings, close tags properly, and ensure alt attributes are present.
▸Raw Markdown sent to the LLM
# Site Audit — https://www.sorainen.com/et/
Run: 2026-08-12T11:03:54.261Z

Audited **10** of 10 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://www.sorainen.com/et
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

---

# Page 1 of 10 — https://www.sorainen.com/et

Run: 2026-08-12T11:03:58.794Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 19481 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **57** | 78 |
| Accessibility | 77 | 77 |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.5 s** / 1391 ms p75 (fast) | 2.0 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.007** / 0 p75 (fast) |
| TBT | **318 ms** | 266 ms |
| FCP | **3.07 s** / 1137 ms p75 (fast) | 767 ms / 917 ms p75 (fast) |
| Speed Index | **5.95 s** | 1.67 s |
| TTFB | **3 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.5 s
2. **total-blocking-time** (low) — 320 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (high) — 6.0 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 72 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1754389560 — 38 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 148 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 147 ms
- https://connect.facebook.net/en_US/fbevents.js — 146 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 122 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 87 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 80 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 72 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 71 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.5 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `total-blocking-time` (performance, score 0.77, weight 30) — Total Blocking Time — 320 ms
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.47, weight 10) — Speed Index — 6.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.07, weight 0) — Time to Interactive — 15.2 s
- `max-potential-fid` (performance, score 0.84, weight 0) — Max Potential First Input Delay — 150 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 403 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 09:14:17 GMT
- expires: Wed, 12 Aug 2026 11:03:59 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 14051
- Decoded body: 58.2 KB
- Compression ratio: 0.236

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 14051
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:03:59 GMT
expires: Wed, 12 Aug 2026 11:03:59 GMT
keep-alive: timeout=5, max=98
last-modified: Wed, 12 Aug 2026 09:14:17 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1113 ms._

**Scoring:** 16 errors · 9 warnings · 33 cosmetic (suppressed)

> **Validator truncated at line 407** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 407** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (high) — x12, first at line 255
3. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 53
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 407
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 407

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 5 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 53 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 103 `33;" />
		<script type="text/javascript">
			(f`
- (×12) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 255 `<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/img/line__ho`
- (×2) [warning] Empty heading. — first at line 272 `<h2></h2>`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 334 `<section class="homePeople bg-purple">
			<d`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 407 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`
- (×1) [error] End tag “a” violates nesting rules. — first at line 407 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 407 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/aku-sorainen/">Aku So`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3503 ms._

**Scoring:** 8 violations · 46 passes · critical 2 · serious 3 · moderate 2 · minor 1

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.headerSearch__toggle.col-tp-none.col-m-none`
- `.submit`
- `.close`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `.current_page_parent > a`
- … and 5 more nodes

#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `#slick-slide00 > a[target="_self"] > .homeHeroSlider__main > h2`

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.homeHero__line1`
- `.homeHero__line2`
- `.line__homePeople_1`
- `.line__homePeople_2`
- `.line__homePeople_3`
- … and 3 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `h1`
- `.homeHero__line1`
- `.homeHero__quote`
- … and 16 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3518 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 71 network requests · 18.45 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 20 | 1.18 MB |
| image | 27 | 1.13 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 7 | 76.7 KB |
| document | 3 | 13.7 KB |
| fetch | 6 | 44 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (script) — 577 ms, 188.3 KB
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 432 ms, 335.7 KB
- https://www.sorainen.com/et (document) — 323 ms, 0 B
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/translations/I3SugJ7c.json (fetch) — 272 ms, 0 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 237 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532639235&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=443746982&_eu=AAAAAGAC&are=1&cid=1539874144.1786532640&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896802~120125304&sid=1786532640&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1312 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532639235&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=443746982&_eu=AAAAAGAC&are=1&cid=1539874144.1786532640&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119527020~119896802~120125304&sid=1786532640&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1312 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=v65sczrjumsf)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=v65sczrjumsf)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3518 ms._

**Document:**
- Lang: et
- Title: Advokaadibüroo Sorainen
- Canonical: https://www.sorainen.com/et/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 99953

**Meta tags:**
- Description: Oleme äriõigusele keskendunud regionaalne advokaadibüroo, kus Eesti, Läti ja Leedu kontorid tegutsevad ühtse tervikuna.
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×6, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Aitame klientidel olla äris edukad
  - h2: 
  - h2: 
  - h2: Eesti edu võti on kiirus ja vägevad põlvkonnad
  - h2: Meiega liitus Eesti tuntumaid ja kogenumaid tehingunõustajaid Sven Papp
  - h2: Värsked edetabelid kinnitavad meie positsiooni Baltikumi tippbüroona
  - h2: Nõustamisvaldkonnad
  - h3: Eva Berlaus, juhtivpartner
  - h3: Eva Berlaus, juhtivpartner
  - h2: Uudised
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 37 total — 1 defer, 6 async, 11 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1754389560
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1754389560
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 3 external, 6 inline (26.6 KB)

**Images:** 21 total — **12 without alt**, **16 without width/height**, 19 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_2.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ent/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif | _(empty)_ | 1142×1243 | _n/a_ | ✗ |
| wp-content/uploads/2025/11/new-horizons-with-sorainen-ee.png | Tekst: „Koos jõuame kaugemale – aitame e | 1142×1243 | _n/a_ | ✓ |
| uploads/2026/07/soraineni-sagedus-edukas-eesti-thumbnail.png | Soraineni Sagedus Edukas Eesti Kaupo Lep | 1080×1080 | _n/a_ | ✓ |
| m/wp-content/uploads/2026/04/sven-papp-ee-web-front-page.png | Ühinemiste ja ülevõtmiste, ühingu- ja tö | 1142×1243 | lazy | ✓ |
| nd-legal-500-2026-campaign-web-first-page-1142-x-1243-px.png | Top tier firm. Legal500. Chambers top ra | 1142×1243 | lazy | ✓ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| /wp-content/themes/sorainen/build/img/line__homePeople_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/line__homePeople_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 70 anchors — 6 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "nõustamisvaldkonnad" ×5
- "uudised" ×3
- "sorainen" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "näita kõiki uudiseid" ×2
- "eva berlaus" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- search — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **12 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
3. **16 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **11 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (16 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/5 raster images use srcset or <picture> (80%) (16 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 11 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: …ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.expertiseIntro__img.bg-cover`
  - `url: …sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-500x738.jpg`
  - `box: 419×624px`
- Responsive images (srcset / <picture>):
  - `…ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
- Reasonable number of image sizes:
  - `widths: 46, 50, 150, 240, 310, 500, 541, 589, 768, 1080, 1142`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 10 — https://www.sorainen.com/newsroom

Run: 2026-08-12T11:03:58.796Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 18430 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **52** | 82 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.6 s** / 1391 ms p75 (fast) | 1.0 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **570 ms** | 338 ms |
| FCP | **3.05 s** / 1137 ms p75 (fast) | 785 ms / 917 ms p75 (fast) |
| Speed Index | **4.81 s** | 1.53 s |
| TTFB | 3 ms / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 11.6 s
2. **total-blocking-time** (medium) — 570 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (medium) — 4.8 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 204 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 168 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 158 ms
- https://connect.facebook.net/en_US/fbevents.js — 132 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 110 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 88 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 82 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 74 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 73 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 69 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.6 s
- `total-blocking-time` (performance, score 0.52, weight 30) — Total Blocking Time — 570 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.67, weight 10) — Speed Index — 4.8 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.2 s
- `max-potential-fid` (performance, score 0.65, weight 0) — Max Potential First Input Delay — 200 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 378 ms._

**Transport:**
- Final URL: https://www.sorainen.com/newsroom/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:00:38 GMT
- expires: Wed, 12 Aug 2026 11:03:59 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19207
- Decoded body: 79.7 KB
- Compression ratio: 0.235

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19207
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:03:59 GMT
expires: Wed, 12 Aug 2026 11:03:59 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:00:38 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1228 ms._

**Scoring:** 10 errors · 15 warnings · 76 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-adc4a003”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-insurance”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-50-8002b801-adc4a006”.** (medium) — x1, first at line 356

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/newsletter/" class="btn btn-primary btn-primar`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a003”. — first at line 356 `s</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a003” was here. — first at line 356 `g</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [error] Duplicate ID “select-insurance”. — first at line 356 `s</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [warning] The first occurrence of ID “select-insurance” was here. — first at line 356 `t</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a006”. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a006” was here. — first at line 356 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c0d”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c0d” was here. — first at line 356 `n</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 452 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 457 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">No res`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 4259 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 4271 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 18.8 KB |
| xhr | 2 | 2.7 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 563 ms, 138.6 KB
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (script) — 561 ms, 862 B
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=en&order=DESC&orderby=date&currentPage=2 (xhr) — 515 ms, 2.7 KB
- https://www.sorainen.com/newsroom (document) — 513 ms, 0 B
- https://www.sorainen.com/wp-content/plugins/contact-form-7/includes/swv/js/index.js?ver=6.1.6 (script) — 503 ms, 3.4 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532639441&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1766089638&_eu=AAAAAGAC&are=1&cid=585739197.1786532640&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896802~120125304~120385422&sid=1786532640&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1542 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532639441&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1766089638&_eu=AAAAAGAC&are=1&cid=585739197.1786532640&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896802~120125304~120385422&sid=1786532640&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1542 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=lonkkwv378nj)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=lonkkwv378nj)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 4270 ms._

**Document:**
- Lang: en-US
- Title: Newsroom - Sorainen
- Canonical: https://www.sorainen.com/newsroom/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 133851

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: No results
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: Sorainen awarded IFLR Baltic Law Firm of the Year 2026 for record 10th time for 
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h3: Sorainen awarded Baltic Law Firm of the Year at the Chambers Europe 2026 ceremon
  - h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
  - h3: We strengthen Dispute Resolution and ESG capabilities with the addition of attor
  - h3: Baltic Deals of the Year 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Join our newsletter!
  - h3: Search news
  - h3: Keyword
  - h3: Sector
  - h3: Service
  - h3: Country
  - h3: Date
  - h3: Date
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 6 inline (26.6 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 93 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×6
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "saulė dagilytė" ×2
- "laimonas skibarka" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 10 — https://www.sorainen.com/et/uudised

Run: 2026-08-12T11:04:17.226Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 23197 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **59** | 68 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.9 s** / 1391 ms p75 (fast) | 1.2 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | 612 ms | **691 ms** |
| FCP | **3.10 s** / 1137 ms p75 (fast) | 799 ms / 917 ms p75 (fast) |
| Speed Index | **4.58 s** | 1.88 s |
| TTFB | **16 ms** / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.9 s
2. **total-blocking-time** (high) — 610 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.6 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 202 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 168 ms
- https://connect.facebook.net/en_US/fbevents.js — 163 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 142 ms
- _lighthouse-eval.js — 126 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 104 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 80 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 77 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 76 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 68 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.29, weight 25) — Largest Contentful Paint — 4.9 s
- `total-blocking-time` (performance, score 0.49, weight 30) — Total Blocking Time — 610 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.71, weight 10) — Speed Index — 4.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.11, weight 0) — Time to Interactive — 13.5 s
- `max-potential-fid` (performance, score 0.66, weight 0) — Max Potential First Input Delay — 200 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 352 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/uudised/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 03:15:39 GMT
- expires: Wed, 12 Aug 2026 11:04:17 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 20201
- Decoded body: 82.2 KB
- Compression ratio: 0.24

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 20201
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:17 GMT
expires: Wed, 12 Aug 2026 11:04:17 GMT
keep-alive: timeout=5, max=100
last-modified: Wed, 12 Aug 2026 03:15:39 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1065 ms._

**Scoring:** 8 errors · 12 warnings · 79 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 359
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 54
3. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 357
4. **Duplicate ID “select-kapitaliturud”.** (medium) — x1, first at line 359
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 459

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 54 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 100 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 357 `<a href="https://www.sorainen.com/et/uudiskiri/" class="btn btn-primary btn-prim`
- (×3) [error] No space between attributes. — first at line 359 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-kapitaliturud”. — first at line 359 `)</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [warning] The first occurrence of ID “select-kapitaliturud” was here. — first at line 359 `s</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 459 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 464 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 268 `<h2 class="postsEmpty__title">Tulemu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3291 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `#footer-menu > .current_page_parent.current_page_parent-type-post_type.current_page_parent-object-page > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3302 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.7 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=et&order=DESC&orderby=date&currentPage=2 (xhr) — 511 ms, 3.1 KB
- https://www.sorainen.com/et/uudised (document) — 460 ms, 0 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 379 ms, 668 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 366 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 221 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532657808&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1942526371&_eu=AAAAAGAC&are=1&cid=2053832896.1786532658&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119381662~119527019~119896802~120125304~120315584&sid=1786532658&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Uudised%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=997 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532657808&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1942526371&_eu=AAAAAGAC&are=1&cid=2053832896.1786532658&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938465~115938468~118897920~118897930~119367802~119367810~119381662~119527019~119896802~120125304~120315584&sid=1786532658&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Uudised%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=997 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3z4gobbblghx)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3z4gobbblghx)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3302 ms._

**Document:**
- Lang: et
- Title: Uudised - Sorainen
- Canonical: https://www.sorainen.com/et/uudised/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 136603

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Tulemusi ei leitud
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
  - h3: Kohaliku omavalitsuse uudised: olulised muudatused ehituses, hariduses ja tarist
  - h3: Sorainen valiti Chambers Europe 2026 galal Balti riikide aasta advokaadibürooks
  - h3: Eduka Eesti võitis idee luua Eesti ettevõtete kaitseliit
  - h3: 2026. aasta suurtehingud tegid Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Maksu-uudised: vabatahtlik reserv omakapitali sissemaksena, Eesti maksutahtest j
  - h3: Meie partneriteringiga on liitunud Eesti tuntumaid ja kogenumaid tehingunõustaja
  - h3: Soovid meie uudiskirju?
  - h3: Otsi uudiseid
  - h3: Märksõna
  - h3: Ärivaldkond
  - h3: Õigusvaldkond
  - h3: Riik
  - h3: Kuupäev
  - h3: Kuupäev
  - h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 87 anchors — 8 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×4
- "uudised" ×3
- "kaupo lepasepp" ×3
- "sorainen" ×2
- "nõustamisvaldkonnad" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "iris magnus" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 10 — https://www.sorainen.com/lv/zinas

Run: 2026-08-12T11:04:18.275Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20142 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **60** | 91 |
| Accessibility | 85 | **81** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.9 s** / 1391 ms p75 (fast) | 1.1 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | **728 ms** | 173 ms |
| FCP | **3.10 s** / 1137 ms p75 (fast) | 793 ms / 917 ms p75 (fast) |
| Speed Index | **5.36 s** | 1.55 s |
| TTFB | 3 ms / 680 ms p75 (fast) | **11 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (high) — 730 ms
2. **largest-contentful-paint** (medium) — 3.9 s
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 5.4 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68b0h2 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68b0h2 — 176 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 171 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 165 ms
- https://connect.facebook.net/en_US/fbevents.js — 150 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 136 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 114 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 92 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 91 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 85 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 77 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.41, weight 30) — Total Blocking Time — 730 ms
- `largest-contentful-paint` (performance, score 0.51, weight 25) — Largest Contentful Paint — 3.9 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.57, weight 10) — Speed Index — 5.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.11, weight 0) — Time to Interactive — 13.4 s
- `max-potential-fid` (performance, score 0.75, weight 0) — Max Potential First Input Delay — 180 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 357 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lv/zinas/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Wed, 12 Aug 2026 10:06:16 GMT
- expires: Wed, 12 Aug 2026 11:04:18 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19600
- Decoded body: 80.7 KB
- Compression ratio: 0.237

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 19600
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:18 GMT
expires: Wed, 12 Aug 2026 11:04:18 GMT
keep-alive: timeout=5, max=99
last-modified: Wed, 12 Aug 2026 10:06:16 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1752 ms._

**Scoring:** 11 errors · 16 warnings · 83 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-50-8002b801-ae3c5c07”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-finanses-un-apdrosinasana”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-kapitala-tirgi”.** (medium) — x1, first at line 356

### Issue groups
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/lv/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c07”. — first at line 356 `l</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c07” was here. — first at line 356 `a</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [error] Duplicate ID “select-finanses-un-apdrosinasana”. — first at line 356 `a</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [warning] The first occurrence of ID “select-finanses-un-apdrosinasana” was here. — first at line 356 `i</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [error] Duplicate ID “select-kapitala-tirgi”. — first at line 356 `)</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [warning] The first occurrence of ID “select-kapitala-tirgi” was here. — first at line 356 `a</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [error] Duplicate ID “select-nekustamais-ipasums-un-buvnieciba”. — first at line 356 `a</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums-un-buvnieciba” was here. — first at line 356 `i</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [error] Duplicate ID “select-buvnieciba”. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [warning] The first occurrence of ID “select-buvnieciba” was here. — first at line 356 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [error] Duplicate ID “select-nekustamais-ipasums”. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums” was here. — first at line 356 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 455 `m>
</div>
</p>
    <`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">Nekas`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3205 ms._

**Scoring:** 8 violations · 49 passes · critical 3 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5485 > a`
- `#menu-item-5486 > a`
- `#menu-item-115921 > a`
- `#footer-menu > .menu-item-104920.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5489 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3216 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 65 network requests · 1.81 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.1 KB |
| xhr | 2 | 3.0 KB |
| fetch | 8 | 809 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lv&order=DESC&orderby=date&currentPage=2 (xhr) — 511 ms, 3.0 KB
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/feedback/schema (fetch) — 395 ms, 763 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/refill (fetch) — 365 ms, 2 B
- https://www.sorainen.com/lv/zinas (document) — 340 ms, 0 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 251 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532658709&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1838679654&_eu=AAAAAGAC&are=1&cid=830444263.1786532659&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118395333~118897920~118897930~119367802~119367810~119404701~119527019~119896802~120125304~120315583&sid=1786532659&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=904 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532658709&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1838679654&_eu=AAAAAGAC&are=1&cid=830444263.1786532659&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=18&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118395333~118897920~118897930~119367802~119367810~119404701~119527019~119896802~120125304~120315583&sid=1786532659&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=904 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=99nzmm4nl9n)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=99nzmm4nl9n)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3216 ms._

**Document:**
- Lang: lv-LV
- Title: Ziņas - Sorainen
- Canonical: https://www.sorainen.com/lv/zinas/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 133955

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nekas netika atrasts
  - h3: Palīdzam privātajiem klientiem aizsargāt un vairot kapitālu: Chambers reitingā S
  - h3: Sorainen publicē Ilgtspējas ziņojumu 2026: atbildīga izaugsme un disciplinēts pr
  - h3: iFinanses.lv: Kādos autopārvadājumos no 1. jūlija nepieciešams tahogrāfs?
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen kļūst par “Liepāja 2027” juridisko partneri ceļā uz Eiropas kultūras ga
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen ir atzīts par Gada advokātu biroju Baltijā Chambers Europe 2026 apbalvo
  - h3: Sorainen kļūst par Latvijas E‑komercijas Asociācijas sadarbības partneri
  - h3: Sorainen turpina atbalstīt Rīgas Juridiskās augstskolas bibliotēku
  - h3: Baltijas gada darījumi 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCap 
  - h3: Piesakieties jaunumiem!
  - h3: Meklēt ziņas
  - h3: Atslēgvārds
  - h3: Sektors
  - h3: Pakalpojums
  - h3: Valsts
  - h3: Datums
  - h3: Datums
  - h4: Vai jūs interesē juridiskie jaunumi reģionā?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 50 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 73 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "ziņas" ×3
- "sorainen" ×2
- "specializācija" ×2
- "komanda" ×2
- "karjera" ×2
- "par mums" ×2
- "kontakti" ×2
- "augustas klezys" ×2
- "piret jesse" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 10 — https://www.sorainen.com/lt/naujienos

Run: 2026-08-12T11:04:38.417Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 20326 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **65** | 75 |
| Accessibility | 85 | **77** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.0 s** / 1391 ms p75 (fast) | 1.0 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.004** / 0 p75 (fast) |
| TBT | **590 ms** | 460 ms |
| FCP | **3.07 s** / 1137 ms p75 (fast) | 783 ms / 917 ms p75 (fast) |
| Speed Index | **4.44 s** | 1.72 s |
| TTFB | 3 ms / 680 ms p75 (fast) | 3 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **total-blocking-time** (medium) — 590 ms
2. **largest-contentful-paint** (medium) — 4.0 s
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.4 s
5. **cache-insight** (medium) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 194 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 169 ms
- https://connect.facebook.net/en_US/fbevents.js — 161 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 146 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 132 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 93 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 92 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 89 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 88 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 72 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `total-blocking-time` (performance, score 0.50, weight 30) — Total Blocking Time — 590 ms
- `largest-contentful-paint` (performance, score 0.50, weight 25) — Largest Contentful Paint — 4.0 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.47, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.73, weight 10) — Speed Index — 4.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.1 s
- `max-potential-fid` (performance, score 0.69, weight 0) — Max Potential First Input Delay — 190 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 390 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lt/naujienos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:39 GMT
- expires: Wed, 12 Aug 2026 11:04:38 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19854
- Decoded body: 80.7 KB
- Compression ratio: 0.24

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19854
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:38 GMT
expires: Wed, 12 Aug 2026 11:04:38 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:19:39 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1159 ms._

**Scoring:** 12 errors · 17 warnings · 76 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 356
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 354
3. **Duplicate ID “select-finansai-ir-draudimas”.** (medium) — x1, first at line 356
4. **Duplicate ID “select-draudimas”.** (medium) — x1, first at line 356
5. **Duplicate ID “select-kapitalo-rinkos”.** (medium) — x1, first at line 356

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×9) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 354 `<a href="https://www.sorainen.com/lt/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 356 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-finansai-ir-draudimas”. — first at line 356 `a</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [warning] The first occurrence of ID “select-finansai-ir-draudimas” was here. — first at line 356 `s</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [error] Duplicate ID “select-draudimas”. — first at line 356 `s</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [warning] The first occurrence of ID “select-draudimas” was here. — first at line 356 `ė</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [error] Duplicate ID “select-kapitalo-rinkos”. — first at line 356 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [warning] The first occurrence of ID “select-kapitalo-rinkos” was here. — first at line 356 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas-ir-statyba”. — first at line 356 `i</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas-ir-statyba” was here. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas”. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas” was here. — first at line 356 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [error] Duplicate ID “select-statyba”. — first at line 356 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [warning] The first occurrence of ID “select-statyba” was here. — first at line 356 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 456 `m>
</div>
</p>
    <`
- (×1) [error] Attribute “pause” not allowed on element “video” at this point. — first at line 461 `ide">
    <video id="splashVideo" width="1920" height="1080" pause controls post`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 265 `<h2 class="postsEmpty__title">Nėra r`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3370 ms._

**Scoring:** 9 violations · 48 passes · critical 3 · serious 3 · moderate 3 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-115923 > a`
- `#menu-item-5498 > a`
- `a[aria-current="page"]`
- `#menu-item-115926 > a`
- `#menu-item-5501 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3381 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 66 network requests · 17.42 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 27 | 1.22 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.4 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 798 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.9 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lt&order=DESC&orderby=date&currentPage=2 (xhr) — 534 ms, 3.1 KB
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/feedback/schema (fetch) — 511 ms, 752 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/refill (fetch) — 481 ms, 2 B
- https://www.sorainen.com/lt/naujienos (document) — 349 ms, 0 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 276 ms, 335.7 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532678862&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=371406104&_eu=AAAAAGAC&are=1&cid=137958581.1786532679&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404700~119404702~119527019~119896803~120125305&sid=1786532679&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=910 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532678862&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=371406104&_eu=AAAAAGAC&are=1&cid=137958581.1786532679&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=8&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938469~118897920~118897930~119367802~119367810~119404700~119404702~119527019~119896803~120125305&sid=1786532679&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=910 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=1zwcrdjhydgd)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=1zwcrdjhydgd)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3381 ms._

**Document:**
- Lang: lt-LT
- Title: Naujienos - Sorainen
- Canonical: https://www.sorainen.com/lt/naujienos/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 135242

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nėra rezultatų
  - h3: Privatiems klientams padedame apsaugoti, auginti ir perduoti turtą ateities kart
  - h3: Mokesčių naujienos: 2026 m. antrasis ketvirtis
  - h3: „Sorainen“ paskelbė 2026 m. tvarumo ataskaitą: atsakingas augimas per kryptingą 
  - h3: „Sorainen“ jau rekordinį dešimtą kartą pripažinta IFLR Baltijos metų teisės firm
  - h3: „Sorainen“ pripažinta Baltijos šalių metų teisės firma „Chambers Europe“ 2026 m.
  - h3: Stipriname ginčų ir ESG kompetencijas: prie komandos jungiasi advokatė Renata Ja
  - h3: 2026 metų Baltijos sandoriai: „Salling Group“, „Tele2“ / „Manulife“, „nexos.ai“,
  - h3: „Sorainen“ reikšmingai stiprina savo komandą: daugiausiai partnerių ir stipriaus
  - h3: „Sorainen“ paskyrė tris naujus partnerius
  - h3: Mūsų komanda pelnė pirmas pozicijas „Chambers FinTech 2026“ reitinguose visose B
  - h3: Užsisakykite mūsų naujienlaiškį!
  - h3: Ieškoti naujienų
  - h3: Raktiniai žodžiai
  - h3: Sektorius
  - h3: Paslauga
  - h3: Šalis
  - h3: Data
  - h3: Data
  - h4: Domina aktualios verslo teisės naujienos?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 51 total — 1 defer, 6 async, 18 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68b0h2 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 6 inline (26.6 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 88 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "naujienos" ×3
- "saulė dagilytė" ×3
- "dr mindaugas lukas" ×3
- "sorainen" ×2
- "paslaugos" ×2
- "komanda" ×2
- "karjera" ×2
- "apie mus" ×2
- "kontaktai" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **18 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 6 of 10 — https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus

Run: 2026-08-12T11:04:40.423Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 14366 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **67** | 98 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **12.1 s** / 1391 ms p75 (fast) | 0.9 s / 1059 ms p75 (fast) |
| CLS | **0.004** / 0 p75 (fast) | 0.003 / 0 p75 (fast) |
| TBT | **93 ms** | 79 ms |
| FCP | **3.06 s** / 1137 ms p75 (fast) | 778 ms / 917 ms p75 (fast) |
| Speed Index | **4.14 s** | 1.23 s |
| TTFB | 2 ms / 680 ms p75 (fast) | **3 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 12.1 s
2. **first-contentful-paint** (high) — 3.1 s
3. **speed-index** (low) — 4.1 s
4. **cache-insight** (high) — Est savings of 99 KiB
5. **document-latency-insight** (high) — Est savings of 400 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.004

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 92 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 84 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 76 ms
- https://connect.facebook.net/en_US/fbevents.js — 75 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 12.1 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.78, weight 10) — Speed Index — 4.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.14, weight 0) — Time to Interactive — 12.5 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 346 ms._

**Transport:**
- Final URL: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:44 GMT
- expires: Wed, 12 Aug 2026 11:04:40 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16547
- Decoded body: 64.1 KB
- Compression ratio: 0.252

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 16547
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:40 GMT
expires: Wed, 12 Aug 2026 11:04:40 GMT
keep-alive: timeout=5, max=99
last-modified: Tue, 11 Aug 2026 17:19:44 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 852 ms._

**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)

> **Validator truncated at line 306** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 306** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 284
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 297
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 306
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 306

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 284 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 297 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 306 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3037 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3050 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 62 network requests · 17.39 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 453 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 402 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 369 ms, 138.6 KB
- https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus (document) — 357 ms, 0 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 329 ms, 335.7 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532680901&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1171057905&_eu=AAAAAGAC&are=1&cid=1328179890.1786532681&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119381664~119404702~119527019~119896802~120125304~120385423&sid=1786532681&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=931 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532680901&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1171057905&_eu=AAAAAGAC&are=1&cid=1328179890.1786532681&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=17&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~119381664~119404702~119527019~119896802~120125304~120385423&sid=1786532681&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flaw-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus%2F&dt=Law%20firm%20ratings%20in%20Mergermarket%20place%20SORAINEN%20as%20a%20leader%20in%20the%20Baltics%20and%20Belarus%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=931 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=jg8rutjqrmob)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=jg8rutjqrmob)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3050 ms._

**Document:**
- Lang: en-US
- Title: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and Belarus - Sorainen
- Canonical: https://www.sorainen.com/law-firm-ratings-in-mergermarket-place-sorainen-as-a-leader-in-the-baltics-and-belarus/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106815

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Law firm ratings in Mergermarket place SORAINEN as a leader in the Baltics and B
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 64 anchors — 16 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 7 of 10 — https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen

Run: 2026-08-12T11:04:54.790Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 34541 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **42** | 97 |
| Accessibility | 81 | 81 |
| Best Practices | **69** | 73 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **9.3 s** / 1391 ms p75 (fast) | 0.9 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | **1.30 s** | 62 ms |
| FCP | **3.05 s** / 1137 ms p75 (fast) | 817 ms / 917 ms p75 (fast) |
| Speed Index | **4.61 s** | 1.40 s |
| TTFB | **7 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 9.3 s
2. **total-blocking-time** (high) — 1,300 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (medium) — 4.6 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 163 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 308 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 255 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 240 ms
- https://connect.facebook.net/en_US/fbevents.js — 208 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 166 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 159 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 142 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 126 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 117 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 112 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `httpsOk`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.01, weight 25) — Largest Contentful Paint — 9.3 s
- `total-blocking-time` (performance, score 0.18, weight 30) — Total Blocking Time — 1,300 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.1 s
- `is-on-https` (best-practices, score 0.00, weight 5) — Does not use HTTPS — 1 insecure request found
- `speed-index` (performance, score 0.70, weight 10) — Speed Index — 4.6 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.11, weight 0) — Time to Interactive — 13.4 s
- `max-potential-fid` (performance, score 0.34, weight 0) — Max Potential First Input Delay — 310 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 392 ms._

**Transport:**
- Final URL: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:19:46 GMT
- expires: Wed, 12 Aug 2026 11:04:55 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 16572
- Decoded body: 64.4 KB
- Compression ratio: 0.251

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 16572
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:55 GMT
expires: Wed, 12 Aug 2026 11:04:55 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:19:46 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1142 ms._

**Scoring:** 5 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 298** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 298** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 276
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 289
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 298
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 298

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 276 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 289 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 298 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3031 ms._

**Scoring:** 7 violations · 47 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3046 ms._

**Capture summary:** 10 console events · 0 mixed-content requests · 63 network requests · 17.40 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 54.7 KB |
| document | 3 | 16.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.9 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 516 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 353 ms, 2 B
- https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen (document) — 327 ms, 0 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 240 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 229 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532695354&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=130045402&_eu=AAAAAGAC&are=1&cid=2000063384.1786532696&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896803~120125304&sid=1786532695&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=996 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532695354&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=130045402&_eu=AAAAAGAC&are=1&cid=2000063384.1786532696&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=19&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938469~118897920~118897930~119367802~119367810~119404703~119527020~119896803~120125304&sid=1786532695&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fdarius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen%2F&dt=Darius%20Raulu%C3%B0aitis%2C%20former%20Prosecutor%20General%2C%20joins%20law%20firm%20SORAINEN%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=996 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [warning] Mixed Content: The page at 'https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/' was loaded over HTTPS, but requested an insecure element 'http://www.sorainen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg'. This request was automatically upgraded to HTTPS, For more information see https://blog.chromium.org/2019/10/no-more-mixed-messages-about-https.html (https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/)
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=v9y9wt0259v)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=v9y9wt0259v)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3046 ms._

**Document:**
- Lang: en-US
- Title: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN - Sorainen
- Canonical: https://www.sorainen.com/darius-rauludaitis-former-prosecutor-general-joins-law-firm-sorainen/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 107036

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Darius Rauluðaitis, former Prosecutor General, joins law firm SORAINEN
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68b0h2 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| /content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 58 anchors — 10 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: …nen.com/UserFiles/content%20images/thumbs/__thumb_-2-Darius%20Raulusaitis.jpg`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 8 of 10 — https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards

Run: 2026-08-12T11:04:58.743Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 27489 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | 61 | **60** |
| Accessibility | 78 | 78 |
| Best Practices | **88** | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **12.1 s** / 1391 ms p75 (fast) | 1.8 s / 1059 ms p75 (fast) |
| CLS | 0.001 / 0 p75 (fast) | **0.003** / 0 p75 (fast) |
| TBT | 299 ms | **1.07 s** |
| FCP | **3.10 s** / 1137 ms p75 (fast) | 815 ms / 917 ms p75 (fast) |
| Speed Index | **4.13 s** | 1.95 s |
| TTFB | **3 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 12.1 s
2. **total-blocking-time** (low) — 300 ms
3. **first-contentful-paint** (high) — 3.1 s
4. **speed-index** (low) — 4.1 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Layout-shift sources
- article.postView > div.container > div.postContent > p — shift 0.001

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 127 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 112 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 111 ms
- https://connect.facebook.net/en_US/fbevents.js — 108 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 95 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 72 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 69 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 65 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 54 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 12.1 s
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `total-blocking-time` (performance, score 0.79, weight 30) — Total Blocking Time — 300 ms
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `speed-index` (performance, score 0.79, weight 10) — Speed Index — 4.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.12, weight 0) — Time to Interactive — 13.0 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 364 ms._

**Transport:**
- Final URL: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:51 GMT
- expires: Wed, 12 Aug 2026 11:04:59 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 17562
- Decoded body: 67.4 KB
- Compression ratio: 0.255

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 17562
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:04:59 GMT
expires: Wed, 12 Aug 2026 11:04:59 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:06:51 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1104 ms._

**Scoring:** 20 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 311** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 311** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content.** (high) — x7, first at line 261
3. **Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.)** (high) — x5, first at line 261
4. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
5. **Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.)** (medium) — x2, first at line 262

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolin`
- (×5) [error] Element “o_p” not allowed as child of element “span” in this context. (Suppressing further errors from this subtree.) — first at line 261 `ar&rdquo;.<o_p></o_p>`
- (×7) [error] The “o_p” element is a completely-unknown element that is not allowed anywhere in any HTML content. — first at line 261 `ar&rdquo;.<o_p></o_p>`
- (×2) [error] Element “o_p” not allowed as child of element “p” in this context. (Suppressing further errors from this subtree.) — first at line 262 `ed.&rdquo;<o_p></o_p>`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 289 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] End tag “a” violates nesting rules. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 311 `uthor"> / <a href="https://www.sorainen.com/people/carri-ginter/">Dr Car`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3054 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3065 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.40 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 55.6 KB |
| document | 3 | 17.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 903 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 469 ms, 663 B
- https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards (document) — 343 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 342 ms, 2 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 248 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 237 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532699176&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=70485244&_eu=AAAAAGAC&are=1&cid=27246959.1786532700&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119527020~119896803~120315584&sid=1786532699&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=874 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532699176&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=70485244&_eu=AAAAAGAC&are=1&cid=27246959.1786532700&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=1&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118897920~118897930~119367802~119367810~119527020~119896803~120315584&sid=1786532699&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fsorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards%2F&dt=SORAINEN%20named%20%E2%80%9CEuropean%20Law%20Firm%20of%20the%20Year%E2%80%9D%20at%20The%20Lawyer%20European%20Awards%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=874 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=qw89vgbarkcg)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=qw89vgbarkcg)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3065 ms._

**Document:**
- Lang: en-US
- Title: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards - Sorainen
- Canonical: https://www.sorainen.com/sorainen-named-european-law-firm-of-the-year-at-the-lawyer-european-awards/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 109751

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: SORAINEN named “European Law Firm of the Year” at The Lawyer European Awards
  - h2: More like this
  - h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
  - h3: Share your innovative ideas for improving the Estonian healthcare system
  - h3: Second time The Legal500 has recognised us as an ESG-focused firm in the Green G
  - h3: 2023: Year in review
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1h1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 61 anchors — 29 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-Karolina.JPG`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 9 of 10 — https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year

Run: 2026-08-12T11:05:26.233Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 22597 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **46** | 89 |
| Accessibility | 81 | 81 |
| Best Practices | **88** | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.0 s** / 1391 ms p75 (fast) | 1.2 s / 1059 ms p75 (fast) |
| CLS | **0.036** / 0 p75 (fast) | 0.002 / 0 p75 (fast) |
| TBT | **930 ms** | 190 ms |
| FCP | **3.04 s** / 1137 ms p75 (fast) | 800 ms / 917 ms p75 (fast) |
| Speed Index | **4.30 s** | 1.64 s |
| TTFB | **3 ms** / 680 ms p75 (fast) | 2 ms / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.0 s
2. **total-blocking-time** (high) — 930 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (low) — 4.3 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 154 KB wasted
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 153 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted

#### Layout-shift sources
- div#content > article.postView > div.container > div.postContent — shift 0.036

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 358 ms
- https://connect.facebook.net/en_US/fbevents.js — 212 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 207 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 189 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 134 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 110 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 100 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 86 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 75 ms
- https://www.gstatic.com/recaptcha/releases/w_Yb7dGGXaKesJ7BMiqFJqBG/recaptcha__en.js — 75 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.0 s
- `total-blocking-time` (performance, score 0.30, weight 30) — Total Blocking Time — 930 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.76, weight 10) — Speed Index — 4.3 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `image-size-responsive` (best-practices, score 0.00, weight 1) — Serves images with low resolution
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.14, weight 0) — Time to Interactive — 12.6 s
- `max-potential-fid` (performance, score 0.24, weight 0) — Max Potential First Input Delay — 360 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 365 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:53 GMT
- expires: Wed, 12 Aug 2026 11:05:26 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15992
- Decoded body: 63.6 KB
- Compression ratio: 0.245

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15992
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:05:26 GMT
expires: Wed, 12 Aug 2026 11:05:26 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:06:53 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1343 ms._

**Scoring:** 6 errors · 6 warnings · 32 cosmetic (suppressed)

> **Validator truncated at line 295** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 295** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x2, first at line 259
3. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 273
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 295
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 295

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 96 `33;" />
		<script type="text/javascript">
			(f`
- (×2) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 259 `='_blank'><img src='https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 273 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 295 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3198 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `p:nth-child(1) > a[target="_blank"] > img`
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `p:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- … and 4 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3222 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 17.39 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 9 | 53.6 KB |
| document | 3 | 15.6 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.8 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 515 ms, 663 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 381 ms, 2 B
- https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year (document) — 324 ms, 0 B
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1h1 (script) — 282 ms, 188.3 KB
- https://cdn-cookieyes.com/assets/images/close.svg (image) — 269 ms, 0 B

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532726687&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1536737651&_eu=AAAAAGAC&are=1&cid=1261990806.1786532727&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395333~118897920~118897930~119367802~119367810~119404703~119527020~119896803&sid=1786532727&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1049 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68a1h1v898627717z8835828663za20gzb835828663zd835828663&_p=1786532726687&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1536737651&_eu=AAAAAGAC&are=1&cid=1261990806.1786532727&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938469~118395333~118897920~118897930~119367802~119367810~119404703~119527020~119896803&sid=1786532727&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year%2F&dt=Lithuanian%20Private%20Equity%20and%20Venture%20Capital%20Association%20awards%20SORAINEN%20lawyers%20as%20%27Bees%20of%20the%20Year%27%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1049 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=sjhiig7l5ddi)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=sjhiig7l5ddi)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3222 ms._

**Document:**
- Lang: en-US
- Title: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyers as 'Bees of the Year' - Sorainen
- Canonical: https://www.sorainen.com/lithuanian-private-equity-and-venture-capital-association-awards-sorainen-lawyers-as-bees-of-the-year/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 106441

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 7 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Lithuanian Private Equity and Venture Capital Association awards SORAINEN lawyer
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1h1 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 6 total — **2 without alt**, **6 without width/height**, 6 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ps://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 61 anchors — 12 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **2 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **6 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 2 pass · 1 warn · 1 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (5 SVGs excluded). |
| Hero image eagerly loaded | ! warn | Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP. |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 1 raster image on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: https://www.sorainen.com/UserFiles/thumbs/__thumb_-2-VCA-13.jpg`
  - `loading: (not set)`
  - `fetchpriority: (not set)`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero image eagerly loaded** (medium) — Hero image has no explicit loading or fetchpriority (inferred from DOM order/size — Lighthouse LCP element unavailable). Browser default is eager but adding fetchpriority="high" helps LCP.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 10 of 10 — https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys

Run: 2026-08-12T11:05:29.331Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 25072 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **53** | 58 |
| Accessibility | 81 | 81 |
| Best Practices | 92 | 92 |
| SEO | 77 | 77 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.9 s** / 1391 ms p75 (fast) | 2.2 s / 1059 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | 578 ms | **938 ms** |
| FCP | **3.03 s** / 1137 ms p75 (fast) | 787 ms / 917 ms p75 (fast) |
| Speed Index | **4.31 s** | 1.78 s |
| TTFB | 2 ms / 680 ms p75 (fast) | **3 ms** / 687 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 45 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.9 s
2. **total-blocking-time** (medium) — 580 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (low) — 4.3 s
5. **cache-insight** (high) — Est savings of 99 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 164 KB wasted
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 162 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://connect.facebook.net/en_US/fbevents.js — 48 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489 — 45 KB wasted
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1 — 20 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 199 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68a1 — 174 ms
- https://connect.facebook.net/en_US/fbevents.js — 170 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 140 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 101 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 96 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 94 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 89 ms
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js — 81 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 64 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.9 s
- `total-blocking-time` (performance, score 0.51, weight 30) — Total Blocking Time — 580 ms
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `meta-viewport` (accessibility, score 0.00, weight 10) — `[user-scalable="no"]` is used in the `<meta name="viewport">` element or the `[maximum-scale]` attribute is less than 5.
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.49, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.76, weight 10) — Speed Index — 4.3 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.14, weight 0) — Time to Interactive — 12.6 s
- `max-potential-fid` (performance, score 0.67, weight 0) — Max Potential First Input Delay — 200 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 373 ms._

**Transport:**
- Final URL: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Tue, 11 Aug 2026 17:06:55 GMT
- expires: Wed, 12 Aug 2026 11:05:29 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15609
- Decoded body: 61.2 KB
- Compression ratio: 0.249

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15609
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Wed, 12 Aug 2026 11:05:29 GMT
expires: Wed, 12 Aug 2026 11:05:29 GMT
keep-alive: timeout=5, max=100
last-modified: Tue, 11 Aug 2026 17:06:55 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1134 ms._

**Scoring:** 5 errors · 6 warnings · 34 cosmetic (suppressed)

> **Validator truncated at line 297** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 297** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed.** (medium) — x1, first at line 275
3. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (medium) — x1, first at line 288
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 297
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 297

### Issue groups
- (×1) [warning] Consider avoiding viewport values that prevent users from resizing documents. — first at line 6 `="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0, `
- (×5) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 99 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Bad value  for attribute “href” on element “a”: Illegal character in query. Space is not allowed. — first at line 275 `ks__item"><a href="https://www.linkedin.com/shareArticle?mini=true&url=https://w`
- (×1) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 288 `>
        <img src="https://www.sorainen.com/wp-content/themes/sorainen/build/im`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] End tag “a” violates nesting rules. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 297 `uthor"> / <a href="https://www.sorainen.com/people/saule-dagilyte/">Saulė`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3199 ms._

**Scoring:** 7 violations · 48 passes · critical 2 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.search-submit`
- `.col-tp-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.newsIntro__line--2`

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.socialLinks__item:nth-child(1) > a[target="_blank"]`
- `.socialLinks__item:nth-child(2) > a[target="_blank"]`
- `.socialLinks__item:nth-child(3) > a[target="_blank"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 3 more nodes

#### `meta-viewport` (moderate) — WCAG: wcag2aa, wcag144
[Zooming and scaling must not be disabled](https://dequeuniversity.com/rules/axe/4.11/meta-viewport?application=playwright)
- `meta[name="viewport"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `article > .container`
- `.postFooter__title`
- `section`
- … and 4 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3208 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 62 network requests · 17.39 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| media | 1 | 15.61 MB |
| script | 26 | 1.20 MB |
| other | 1 | 335.7 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 8 | 48.3 KB |
| document | 3 | 15.2 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 1.03 MB
- https://www.googletagmanager.com — 2 requests, 326.9 KB
- https://connect.facebook.net — 1 request, 104.5 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys (document) — 432 ms, 0 B
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 430 ms, 663 B
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (script) — 423 ms, 335.7 KB
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 406 ms, 138.6 KB
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 367 ms, 2 B

### Priority fixes
1. **failed request** (medium) — media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532729877&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=628911464&_eu=AAAAAGAC&are=1&cid=588335898.1786532731&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118395333~118897920~118897930~119367802~119367810~119404701~119527019~119896803~120125304&sid=1786532730&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1163 — net::ERR_ABORTED
3. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- media: https://www.sorainen.com/wp-content/themes/sorainen/build/video/splash.webm — net::ERR_ABORTED
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68b0h2v898627717z8835828663za20gzb835828663zd835828663&_p=1786532729877&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=628911464&_eu=AAAAAGAC&are=1&cid=588335898.1786532731&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938465~115938468~118395333~118897920~118897930~119367802~119367810~119404701~119527019~119896803~120125304&sid=1786532730&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fedvins-draba-joins-the-latvian-association-of-patent-attorneys%2F&dt=Edv%C3%AEns%20Draba%20joins%20the%20Latvian%20Association%20of%20Patent%20Attorneys%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1163 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3sfmrfq8sgqy)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=XOqlk8PL_yVx6IdpLbpXdiLy&size=invisible&anchor-ms=20000&execute-ms=30000&cb=3sfmrfq8sgqy)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3208 ms._

**Document:**
- Lang: en-US
- Title: Edvîns Draba joins the Latvian Association of Patent Attorneys - Sorainen
- Canonical: https://www.sorainen.com/edvins-draba-joins-the-latvian-association-of-patent-attorneys/
- Viewport: width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no
- Charset: UTF-8
- HTML bytes: 103975

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×4, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Edvîns Draba joins the Latvian Association of Patent Attorneys
  - h2: More like this
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 47 total — 1 defer, 7 async, 16 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68b0h2 (async)
- https://www.gstatic.com/recaptcha/releases/XOqlk8PL_yVx6IdpLbpXdiLy/recaptcha__en.js (async)
- https://connect.facebook.net/en_US/fbevents.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=496000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.sorainen.com/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1783339489
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1785832165
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.3

**Stylesheets:** 5 external, 5 inline (26.5 KB)

**Images:** 5 total — **1 without alt**, **5 without width/height**, 5 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | cky-close-icon | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | Cookieyes logo | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| ntent/themes/sorainen/build/img/line__newsIntro--2--dark.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 59 anchors — 11 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×3
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "laimonas skibarka" ×2
- "vitalija impolevičienė" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **1 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
2. **5 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **16 render-blocking external scripts** (medium) — Only 1 defer, 7 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (5 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (5 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 4 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.6 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `…om/wp-content/plugins/official-facebook-pixel/js/facebook_signal.js?ver=5.2.2`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 4 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).