20260824T083556Z-869b
- Audited URL
- https://www.sorainen.com/et/
- Timestamp
- 2026-08-24T08:42:04.594Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 66 is the mean of 5 pages. Scores range 62 (https://www.sorainen.com/et) → 70 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.
Audit Report: Advokaadibüroo Sorainen
Website: https://www.sorainen.com/et/
Date: 24.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high
Pages Audited (5 of 5):
- https://www.sorainen.com/et
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
Summary of results
Overall Score: 66 / 100
Status: 🟡 Needs Improvement
Site overall 66 is the mean of 5 pages. Scores range 62 (https://www.sorainen.com/et) → 70 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.
Per-page scores
🟡 Needs Improvement · https://www.sorainen.com/et
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 62 | 52 | 88 | 92 | 92 | 40 |
🟡 Needs Improvement · https://www.sorainen.com/newsroom
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 62 | 58 | 94 | 92 | 85 | 40 |
🟡 Needs Improvement · https://www.sorainen.com/et/uudised
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 72 | 94 | 92 | 92 | 40 |
🟡 Needs Improvement · https://www.sorainen.com/lv/zinas
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 70 | 78 | 94 | 92 | 92 | 40 |
🟡 Needs Improvement · https://www.sorainen.com/lt/naujienos
| Score | Performance | Accessibility | Best Practices | SEO | Security |
|---|---|---|---|---|---|
| 68 | 75 | 94 | 92 | 92 | 40 |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://www.sorainen.com/et | 52 / 86 | 10.16 s / 2.12 s | 0.000 / 0.007 |
| https://www.sorainen.com/newsroom | 58 / 93 | 11.27 s / 1.22 s | 0.000 / 0.000 |
| https://www.sorainen.com/et/uudised | 72 / 93 | 5.19 s / 1.10 s | 0.000 / 0.006 |
| https://www.sorainen.com/lv/zinas | 78 / 93 | 4.06 s / 1.05 s | 0.000 / 0.001 |
| https://www.sorainen.com/lt/naujienos | 75 / 97 | 4.71 s / 1.05 s | 0.000 / 0.004 |
Optimization Checklist
1 of 3 passing — 1 pass · 1 warn · 1 fail · 4 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | N/A | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | N/A | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | Warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | N/A | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Eliminate render-blocking JavaScript and optimize LCP Performance
- Impact: LCP (10.2 s), FCP (3.1 s), TBT (466 ms)
- Problem: 15 render-blocking scripts and heavy third-party JS (Recaptcha, GTM) delay rendering; LCP is 10.2 s on mobile.
- Solution:
- Move non-critical scripts to footer or add
defer/async. - Defer Recaptcha until user interaction (e.g., form focus).
- Convert hero CSS background to
<img>withfetchpriority="high"andsrcset.
- Move non-critical scripts to footer or add
1B. Add alt text to all content images Accessibility
- Impact: WCAG 1.1.1 (Non-text Content), SEO
- Problem: 12 images lack
altattributes (W3C + axe-core critical violations), blocking screen reader users. - Solution:
- Audit all
<img>tags. - Add descriptive
alttext for content images. - Use
alt=""for purely decorative images (e.g., icons, lines).
- Audit all
1C. Harden CSP and HSTS for User-Generated Content Security
- Impact: XSS protection, Transport security
- Problem: Site has user content (
hasUserContent: yes) but CSP allowsunsafe-inline/unsafe-eval; HSTS missingincludeSubDomains. - Solution:
- Remove
'unsafe-inline'and'unsafe-eval'from CSP; use nonces/hashes for scripts. - Update HSTS:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.
- Remove
1D. Defer non-critical JavaScript to fix LCP Performance
- Impact: LCP, FCP, TBT
- Problem: LCP is 11.3 s on mobile; 17 render-blocking scripts and 1.08 MB of JS (reCAPTCHA, GTM) delay rendering.
- Solution:
Add
deferorasyncto non-critical scripts in<head>. Specifically defergtag.js,gtm.js, andrecaptcha__en.jsuntil afterDOMContentLoaded.<script src=".../gtag.js" async></script> <script src=".../recaptcha__en.js" defer></script>
1E. Add accessible labels to forms and buttons Accessibility
- Impact: WCAG 2.1.1, 4.1.2
- Problem: 3 critical axe violations: buttons lack discernible text, form inputs (search, select) lack labels.
- Solution:
Associate
<label>elements with inputs viafor/id. Addaria-labelto icon-only buttons.<label for="search-text">Search</label> <input id="search-text" ...> <button aria-label="Close modal">X</button>
1F. Harden Content Security Policy (CSP) Security
- Impact: XSS protection
- Problem: Site has user-generated content signals, but CSP allows
unsafe-inlineandunsafe-eval, negating XSS defense. - Solution:
Remove
unsafe-inlineandunsafe-evalfromscript-src. Use nonces or hashes for inline scripts.Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
1G. Defer render-blocking scripts to improve LCP Performance
- Impact: LCP (5.2 s), FCP (2.97 s), Speed Index (4.83 s)
- Problem: 17 render-blocking external scripts found in HTML inventory; LCP is 5.2 s on mobile (heavy penalty >4 s).
- Solution:
Add
deferorasyncto non-critical scripts in<head>. Move analytics and third-party widgets to footer.<script src="..." defer></script>
1H. Fix critical form and button accessibility violations Accessibility
- Impact: WCAG 2.1 Level A (button-name, label, select-name)
- Problem: 3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.
- Solution:
- Add
aria-labelor visible text to filter buttons. - Associate
<label>elements with inputs usingfor/id. - Add
aria-labelto<select>elements if visual label is missing.
- Add
1I. Harden Content Security Policy (CSP) for UGC Security
- Impact: XSS protection, Security Headers Grade (40/100)
- Problem: CSP allows
unsafe-inlineandunsafe-evalscripts. Site signals indicate User-Generated Content (UGC) exists, raising XSS risk. - Solution:
Remove
'unsafe-inline'and'unsafe-eval'fromscript-src. Implement nonce-based CSP:Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
1J. Defer render-blocking JavaScript to improve LCP Performance
- Impact: LCP, FCP, Speed Index
- Problem: LCP is 4.1 s on mobile; 17 render-blocking scripts identified including jQuery, GTM, and CookieYes.
- Solution:
Add
deferorasyncto non-critical scripts in<head>. Move jQuery and analytics to footer or load after interaction.<script src="..." defer></script>
1K. Fix critical button and form label violations Accessibility
- Impact: WCAG 2.1.1, 4.1.2
- Problem: 3 critical axe violations: filter buttons lack discernible text; search/select elements lack labels.
- Solution:
Add
aria-labelto icon buttons and associate<label>elements with form inputs.<button aria-label="Filter posts">...</button> <label for="search">Search</label> <input id="search" ...>
1L. Eliminate render-blocking JavaScript Performance
- Impact: LCP, FCP, Speed Index
- Problem: 17 render-blocking scripts found in <head>; LCP is 4.7 s on mobile (target ≤2.5 s).
- Solution:
Add
deferorasyncto non-critical scripts. Move analytics and third-party tags to footer.<script src="..." defer></script>
1M. Fix critical form and button labels Accessibility
- Impact: WCAG 2.4.4, 4.1.2
- Problem: 3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.
- Solution:
Add
aria-labelor visible text to filter buttons and search inputs.<button aria-label="Apply filters">Apply</button> <input aria-label="Search" type="text">
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Fix contrast, labels, and landmarks Accessibility
- Impact: WCAG 1.4.3 (Contrast), 2.4.1 (Bypass Blocks)
- Problem: Menu links fail contrast; search fields lack labels; no
mainlandmark or skip-link. - Solution:
- Increase text contrast to ≥4.5:1.
- Add
<label>oraria-labelto search inputs. - Add
<main>tag and a 'Skip to content' link at the top.
2B. Add H1 and Meta Description SEO
- Impact: Search ranking, CTR
- Problem: W3C reports 0 H1 elements; SEO audit flags missing meta description.
- Solution:
Ensure exactly one
<h1>per page reflecting the main topic. Add<meta name="description" content="...">summarizing the newsroom content.
2C. Complete HSTS Configuration Security
- Impact: Transport security
- Problem: HSTS header present but missing
includeSubDomainsandpreloaddirectives. - Solution:
Update server config to include subdomains and preload flag.
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
2D. Add a single H1 element to the page SEO
- Impact: Document outline, Search ranking
- Problem: HTML inventory shows 0 H1 elements; page starts with H2. W3C validator notes heading structure issues.
- Solution:
Ensure the main page title is wrapped in a single
<h1>tag at the top of the content flow.<h1>Videod - Sorainen</h1>
2E. Fix HTML validation errors and duplicate IDs Best Practices
- Impact: Code quality, Rendering consistency
- Problem: W3C validator reports 7 errors including duplicate ID 'select-kapitaliturud' and malformed attributes (e.g., 'stylr').
- Solution:
- Ensure all IDs are unique.
- Correct attribute typos (e.g.,
stylr→style). - Fix empty
hrefattributes on<link>elements.
2F. Add a unique H1 heading SEO
- Impact: Document outline, Search ranking
- Problem: HTML Inventory confirms 0
<h1>elements; W3C notes no heading level 1. - Solution:
Ensure the page title is wrapped in a single
<h1>tag at the top of the main content.<h1>Ziņas</h1>
2G. Harden HSTS and review CSP Security
- Impact: Transport security, XSS defense
- Problem: HSTS missing
includeSubDomains; CSP allowsunsafe-inlineandunsafe-eval. - Solution:
Update HSTS header to include subdomains. For CSP, remove
unsafe-inlinewhere possible or use nonces.Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
2H. Strengthen HSTS header Security
- Impact: Transport security, downgrade attacks
- Problem: HSTS present but missing
includeSubDomainsandpreloaddirectives (Grade 40/100). - Solution:
Update server config to include subdomains and preload flag.
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
2I. Add H1 and Main landmark SEO
- Impact: Document outline, Screen readers
- Problem: 0
<h1>elements and missing<main>landmark detected in HTML inventory. - Solution:
Ensure exactly one
<h1>per page and wrap primary content in<main>.<h1>Naujienos</h1> <main>...</main>
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Reduce image weight and add dimensions Performance
- Impact: CLS, Page Weight (2.67 MB)
- Problem: 16 images missing width/height attributes; 19 images missing lazy loading.
- Solution:
- Add
widthandheightattributes to all<img>tags. - Ensure
loading="lazy"is present on off-screen images. - Convert remaining PNG/JPEG to WebP/AVIF.
- Add
3B. Fix HTML validation errors Best Practices
- Impact: Code quality, Rendering consistency
- Problem: W3C reports 11 errors including duplicate IDs and invalid attributes (e.g.,
stylr). - Solution:
Audit the HTML source for duplicate
idattributes and correct typos in attribute names. Ensure unique IDs for form elements.
3C. Harden Content Security Policy Security
- Impact: XSS defense-in-depth
- Problem: CSP allows
unsafe-inlineandunsafe-eval, which bypasses XSS protections. - Solution:
Replace
unsafe-inlinewith nonce/hash strategy for scripts and styles.Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
▸Raw Markdown sent to the LLM
# Site Audit — https://www.sorainen.com/et/
Run: 2026-08-24T08:35:56.367Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**
Pages audited:
- https://www.sorainen.com/et
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos
---
# Page 1 of 5 — https://www.sorainen.com/et
Run: 2026-08-24T08:36:01.013Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 22977 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **52** | 86 |
| Accessibility | 88 | **84** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.2 s** / 1369 ms p75 (fast) | 2.1 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.007** / 0 p75 (fast) |
| TBT | **466 ms** | 45 ms |
| FCP | **3.10 s** / 1190 ms p75 (fast) | 833 ms / 948 ms p75 (fast) |
| Speed Index | **6.33 s** | 1.85 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 10.2 s
2. **total-blocking-time** (medium) — 470 ms
3. **speed-index** (high) — 6.3 s
4. **first-contentful-paint** (high) — 3.1 s
5. **cache-insight** (medium) — Est savings of 2 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 152 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 72 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 38 KB wasted
#### Long tasks
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 212 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 195 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 172 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 131 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 129 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 110 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 90 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 77 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 73 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 66 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.2 s
- `total-blocking-time` (performance, score 0.61, weight 30) — Total Blocking Time — 470 ms
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `speed-index` (performance, score 0.41, weight 10) — Speed Index — 6.3 s
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.08, weight 0) — Time to Interactive — 14.8 s
- `max-potential-fid` (performance, score 0.62, weight 0) — Max Potential First Input Delay — 210 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 380 ms._
**Transport:**
- Final URL: https://www.sorainen.com/et/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:29:08 GMT
- expires: Mon, 24 Aug 2026 08:36:01 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 15820
- Decoded body: 67.4 KB
- Compression ratio: 0.229
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15820
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:01 GMT
expires: Mon, 24 Aug 2026 08:36:01 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:29:08 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1328 ms._
**Scoring:** 16 errors · 5 warnings · 40 cosmetic (suppressed)
> **Validator truncated at line 412** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.
### Priority fixes
1. **Parser recovery at line 412** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (high) — x12, first at line 260
3. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 59
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 412
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 412
### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 59 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 104 `33;" />
<script type="text/javascript">
(f`
- (×12) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 260 `<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/img/line__ho`
- (×2) [warning] Empty heading. — first at line 277 `<h2></h2>`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 339 `<section class="homePeople bg-purple">
<d`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`
- (×1) [error] End tag “a” violates nesting rules. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 4297 ms._
**Scoring:** 7 violations · 51 passes · critical 2 · serious 3 · moderate 1 · minor 1
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.headerSearch__toggle.col-tp-none.col-m-none`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `.current_page_parent > a`
- … and 5 more nodes
#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `#slick-slide00 > a[target="_self"] > .homeHeroSlider__main > h2`
#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.homeHero__line1`
- `.homeHero__line2`
- `.line__homePeople_1`
- `.line__homePeople_2`
- `.line__homePeople_3`
- … and 3 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.searchBar > .container > .btn-close.btn[href="javascript:;"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 1 more nodes
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `h1`
- `.homeHero__line1`
- `.homeHero__quote`
- … and 20 more nodes
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 4314 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 77 network requests · 2.67 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 27 | 1.12 MB |
| script | 23 | 1.04 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| document | 3 | 15.4 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 573 ms, 138.5 KB
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (script) — 556 ms, 312.4 KB
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (script) — 549 ms, 862 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 485 ms, 668 B
- https://www.sorainen.com/et (document) — 482 ms, 0 B
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561664&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=835472063&_eu=AAAAAGAC&are=1&cid=1130938773.1787560563&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938469~118012008~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1437 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561664&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=835472063&_eu=AAAAAGAC&are=1&cid=1130938773.1787560563&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938469~118012008~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1437 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=htbdv9zge3vz)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=htbdv9zge3vz)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 4314 ms._
**Document:**
- Lang: et
- Title: Advokaadibüroo Sorainen
- Canonical: https://www.sorainen.com/et/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 112224
**Meta tags:**
- Description: Oleme äriõigusele keskendunud regionaalne advokaadibüroo, kus Eesti, Läti ja Leedu kontorid tegutsevad ühtse tervikuna.
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
- en → https://www.sorainen.com/
- et → https://www.sorainen.com/et/
- lv → https://www.sorainen.com/lv/
- lt → https://www.sorainen.com/lt/
- x-default → https://www.sorainen.com/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×6, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Aitame klientidel olla äris edukad
- h2:
- h2:
- h2: Eesti edu võti on kiirus ja vägevad põlvkonnad
- h2: Meiega liitus Eesti tuntumaid ja kogenumaid tehingunõustajaid Sven Papp
- h2: Värsked edetabelid kinnitavad meie positsiooni Baltikumi tippbüroona
- h2: Nõustamisvaldkonnad
- h3: Eva Berlaus, juhtivpartner
- h3: Eva Berlaus, juhtivpartner
- h2: Uudised
- h3: Maksu-uudised: millal tuleb Eestis käibemaksukohustuslasena registreeruda ja kui
- h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
- h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
- h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
- h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 40 total — 1 defer, 5 async, 15 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
**Stylesheets:** 5 external, 6 inline (27.1 KB)
**Images:** 21 total — **12 without alt**, **16 without width/height**, 19 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_2.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ent/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif | _(empty)_ | 1142×1243 | _n/a_ | ✗ |
| wp-content/uploads/2025/11/new-horizons-with-sorainen-ee.png | Tekst: „Koos jõuame kaugemale – aitame e | 1142×1243 | _n/a_ | ✓ |
| uploads/2026/07/soraineni-sagedus-edukas-eesti-thumbnail.png | Soraineni Sagedus Edukas Eesti Kaupo Lep | 1080×1080 | _n/a_ | ✓ |
| m/wp-content/uploads/2026/04/sven-papp-ee-web-front-page.png | Ühinemiste ja ülevõtmiste, ühingu- ja tö | 1142×1243 | lazy | ✓ |
| nd-legal-500-2026-campaign-web-first-page-1142-x-1243-px.png | Top tier firm. Legal500. Chambers top ra | 1142×1243 | lazy | ✓ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| /wp-content/themes/sorainen/build/img/line__homePeople_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/line__homePeople_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 71 anchors — 8 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "nõustamisvaldkonnad" ×5
- "uudised" ×3
- "sorainen" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "näita kõiki uudiseid" ×2
- "dr kaido künnapas" ×2
- "elisabeth lauri" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- search — **no label**
Form 3:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **12 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
3. **16 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **15 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 5 pass · 1 warn · 1 fail
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (16 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/5 raster images use srcset or <picture> (80%) (16 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 11 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- Hero image eagerly loaded:
- `hero: …ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
- `loading: (not set)`
- `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
- `selector: div.expertiseIntro__img.bg-cover`
- `url: ….sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-scaled.jpg`
- `box: 419×624px`
- Responsive images (srcset / <picture>):
- `…ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
- Reasonable number of image sizes:
- `widths: 46, 50, 150, 240, 310, 500, 541, 589, 768, 1080, 1142`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 2 of 5 — https://www.sorainen.com/newsroom
Run: 2026-08-24T08:36:01.015Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 19112 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **58** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 85 | 85 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.3 s** / 1369 ms p75 (fast) | 1.2 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **356 ms** | 127 ms |
| FCP | **3.05 s** / 1190 ms p75 (fast) | 790 ms / 948 ms p75 (fast) |
| Speed Index | **5.04 s** | 1.45 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 11.3 s
2. **total-blocking-time** (medium) — 360 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (medium) — 5.0 s
5. **cache-insight** (medium) — Est savings of 2 KiB
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 166 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 133 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 124 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 83 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 80 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 80 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 71 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 57 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 53 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.3 s
- `total-blocking-time` (performance, score 0.72, weight 30) — Total Blocking Time — 360 ms
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.63, weight 10) — Speed Index — 5.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 11.9 s
- `max-potential-fid` (performance, score 0.78, weight 0) — Max Potential First Input Delay — 170 ms
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 397 ms._
**Transport:**
- Final URL: https://www.sorainen.com/newsroom/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:31:13 GMT
- expires: Mon, 24 Aug 2026 08:36:01 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 18550
- Decoded body: 77.3 KB
- Compression ratio: 0.234
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 18550
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:01 GMT
expires: Mon, 24 Aug 2026 08:36:01 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 24 Aug 2026 08:31:13 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1397 ms._
**Scoring:** 9 errors · 8 warnings · 81 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-50-8002b801-adc4a003”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-insurance”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-50-8002b801-adc4a006”.** (medium) — x1, first at line 358
### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/newsletter/" class="btn btn-primary btn-primar`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a003”. — first at line 358 `s</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a003” was here. — first at line 358 `g</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [error] Duplicate ID “select-insurance”. — first at line 358 `s</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [warning] The first occurrence of ID “select-insurance” was here. — first at line 358 `t</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a006”. — first at line 358 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a006” was here. — first at line 358 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c0d”. — first at line 358 `l</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c0d” was here. — first at line 358 `n</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 454 `m>
</div>
</p>
<`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">No res`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 4294 ms._
**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 4307 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 1.64 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 25 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 18.1 KB |
| xhr | 2 | 2.7 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 543 ms, 663 B
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=en&order=DESC&orderby=date¤tPage=2 (xhr) — 537 ms, 2.7 KB
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 (script) — 495 ms, 190.1 KB
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 434 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 380 ms, 138.6 KB
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561590&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=549162681&_eu=AAAAAGAC&are=1&cid=1661390690.1787560563&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938465~115938469~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1677 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561590&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=549162681&_eu=AAAAAGAC&are=1&cid=1661390690.1787560563&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938465~115938469~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1677 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ip11q44w94xf)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ip11q44w94xf)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 4307 ms._
**Document:**
- Lang: en-US
- Title: Newsroom - Sorainen
- Canonical: https://www.sorainen.com/newsroom/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 132050
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
- en → https://www.sorainen.com/newsroom/
- et → https://www.sorainen.com/et/uudised/
- lv → https://www.sorainen.com/lv/zinas/
- lt → https://www.sorainen.com/lt/naujienos/
- x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: No results
- h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen
- h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
- h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
- h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
- h3: Sorainen awarded IFLR Baltic Law Firm of the Year 2026 for record 10th time for
- h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
- h3: Sorainen awarded Baltic Law Firm of the Year at the Chambers Europe 2026 ceremon
- h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
- h3: We strengthen Dispute Resolution and ESG capabilities with the addition of attor
- h3: Baltic Deals of the Year 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
- h3: Join our newsletter!
- h3: Search news
- h3: Keyword
- h3: Sector
- h3: Service
- h3: Country
- h3: Date
- h3: Date
- h4: Interested in legal updates on business law in the region?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 44 total — 1 defer, 5 async, 17 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
**Stylesheets:** 5 external, 6 inline (27.1 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 93 anchors — 7 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×6
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "saulė dagilytė" ×2
- "laimonas skibarka" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **17 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 3 of 5 — https://www.sorainen.com/et/uudised
Run: 2026-08-24T08:36:20.128Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no
## PageSpeed Insights
_Captured in 15404 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **72** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.2 s** / 1369 ms p75 (fast) | 1.1 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.006** / 0 p75 (fast) |
| TBT | 79 ms | **163 ms** |
| FCP | **2.97 s** / 1190 ms p75 (fast) | 802 ms / 948 ms p75 (fast) |
| Speed Index | **4.83 s** | 1.28 s |
| TTFB | 2 ms / 704 ms p75 (fast) | **3 ms** / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 5.2 s
2. **first-contentful-paint** (medium) — 3.0 s
3. **speed-index** (medium) — 4.8 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 510 ms
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j1h2 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j1h2 — 92 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 79 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 70 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 57 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 55 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.23, weight 25) — Largest Contentful Paint — 5.2 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.51, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.66, weight 10) — Speed Index — 4.8 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 11.9 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 877 ms._
**Transport:**
- Final URL: https://www.sorainen.com/et/uudised/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:20 GMT
- expires: Mon, 24 Aug 2026 08:36:20 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19448
- Decoded body: 79.8 KB
- Compression ratio: 0.238
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19448
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:20 GMT
expires: Mon, 24 Aug 2026 08:36:20 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:20 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1252 ms._
**Scoring:** 7 errors · 5 warnings · 84 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 361
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 59
3. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 359
4. **Duplicate ID “select-kapitaliturud”.** (medium) — x1, first at line 361
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 461
### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 59 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 100 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 359 `<a href="https://www.sorainen.com/et/uudiskiri/" class="btn btn-primary btn-prim`
- (×3) [error] No space between attributes. — first at line 361 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-kapitaliturud”. — first at line 361 `)</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [warning] The first occurrence of ID “select-kapitaliturud” was here. — first at line 361 `s</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 461 `m>
</div>
</p>
<`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 270 `<h2 class="postsEmpty__title">Tulemu`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3731 ms._
**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `#footer-menu > .current_page_parent.current_page_parent-type-post_type.current_page_parent-object-page > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3744 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 1.64 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 25 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.0 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/et/uudised/ (document) — 509 ms, 19.0 KB
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=et&order=DESC&orderby=date¤tPage=2 (xhr) — 449 ms, 3.1 KB
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 388 ms, 668 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 378 ms, 2 B
- https://www.sorainen.com/et/uudised (document) — 355 ms, 0 B
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560581066&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1820137604&_eu=AAAAAGAC&are=1&cid=991115098.1787560582&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385423&sid=1787560581&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Videod%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1383 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560581066&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1820137604&_eu=AAAAAGAC&are=1&cid=991115098.1787560582&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385423&sid=1787560581&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Videod%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1383 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=a1b0czzbyuan)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=a1b0czzbyuan)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3744 ms._
**Document:**
- Lang: et
- Title: Videod - Sorainen
- Canonical: https://www.sorainen.com/et/uudised/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 134850
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
- en → https://www.sorainen.com/newsroom/
- et → https://www.sorainen.com/et/uudised/
- lv → https://www.sorainen.com/lv/zinas/
- lt → https://www.sorainen.com/lt/naujienos/
- x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Tulemusi ei leitud
- h3: Maksu-uudised: millal tuleb Eestis käibemaksukohustuslasena registreeruda ja kui
- h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
- h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
- h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
- h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
- h3: Kohaliku omavalitsuse uudised: olulised muudatused ehituses, hariduses ja tarist
- h3: Sorainen valiti Chambers Europe 2026 galal Balti riikide aasta advokaadibürooks
- h3: Eduka Eesti võitis idee luua Eesti ettevõtete kaitseliit
- h3: 2026. aasta suurtehingud tegid Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
- h3: Maksu-uudised: vabatahtlik reserv omakapitali sissemaksena, Eesti maksutahtest j
- h3: Soovid meie uudiskirju?
- h3: Otsi uudiseid
- h3: Märksõna
- h3: Ärivaldkond
- h3: Õigusvaldkond
- h3: Riik
- h3: Kuupäev
- h3: Kuupäev
- h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 45 total — 1 defer, 5 async, 17 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
**Stylesheets:** 5 external, 5 inline (27.0 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 84 anchors — 8 external, 0 preconnect, 1 preload.
Vague repeated link text:
- "eva berlaus" ×4
- "uudised" ×3
- "dr kaido künnapas" ×3
- "sorainen" ×2
- "nõustamisvaldkonnad" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "verner silm" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 4 of 5 — https://www.sorainen.com/lv/zinas
Run: 2026-08-24T08:36:23.990Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 16712 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **78** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** / 1369 ms p75 (fast) | 1.0 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | 100 ms | **156 ms** |
| FCP | **3.05 s** / 1190 ms p75 (fast) | 817 ms / 948 ms p75 (fast) |
| Speed Index | **4.87 s** | 1.41 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **first-contentful-paint** (high) — 3.0 s
3. **speed-index** (medium) — 4.9 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 420 ms
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 152 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 103 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 80 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 62 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 51 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 50 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.48, weight 25) — Largest Contentful Paint — 4.1 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.66, weight 10) — Speed Index — 4.9 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.17, weight 0) — Time to Interactive — 11.8 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 852 ms._
**Transport:**
- Final URL: https://www.sorainen.com/lv/zinas/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:24 GMT
- expires: Mon, 24 Aug 2026 08:36:24 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19517
- Decoded body: 79.7 KB
- Compression ratio: 0.239
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19517
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:24 GMT
expires: Mon, 24 Aug 2026 08:36:24 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:24 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1248 ms._
**Scoring:** 11 errors · 10 warnings · 88 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-50-8002b801-ae3c5c07”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-finanses-un-apdrosinasana”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-kapitala-tirgi”.** (medium) — x1, first at line 358
### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/lv/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c07”. — first at line 358 `l</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c07” was here. — first at line 358 `a</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [error] Duplicate ID “select-finanses-un-apdrosinasana”. — first at line 358 `a</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [warning] The first occurrence of ID “select-finanses-un-apdrosinasana” was here. — first at line 358 `i</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [error] Duplicate ID “select-kapitala-tirgi”. — first at line 358 `)</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [warning] The first occurrence of ID “select-kapitala-tirgi” was here. — first at line 358 `a</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [error] Duplicate ID “select-nekustamais-ipasums-un-buvnieciba”. — first at line 358 `a</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums-un-buvnieciba” was here. — first at line 358 `i</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [error] Duplicate ID “select-buvnieciba”. — first at line 358 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [warning] The first occurrence of ID “select-buvnieciba” was here. — first at line 358 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [error] Duplicate ID “select-nekustamais-ipasums”. — first at line 358 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums” was here. — first at line 358 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 457 `m>
</div>
</p>
<`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">Nekas`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3798 ms._
**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5485 > a`
- `#menu-item-5486 > a`
- `#menu-item-115921 > a`
- `#footer-menu > .menu-item-104920.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5489 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3810 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 64 network requests · 1.65 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 26 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.1 KB |
| xhr | 2 | 3.0 KB |
| fetch | 8 | 809 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lv&order=DESC&orderby=date¤tPage=2 (xhr) — 484 ms, 3.0 KB
- https://www.sorainen.com/lv/zinas/ (document) — 474 ms, 19.1 KB
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (script) — 425 ms, 312.4 KB
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/refill (fetch) — 401 ms, 2 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/feedback/schema (fetch) — 383 ms, 763 B
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0h1v898627717z8835828663za20gzb835828663zd835828663&_p=1787560584887&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=485409269&_eu=AAAAAGAC&are=1&cid=354160805.1787560585&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385422&sid=1787560585&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1480 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0h1v898627717z8835828663za20gzb835828663zd835828663&_p=1787560584887&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=485409269&_eu=AAAAAGAC&are=1&cid=354160805.1787560585&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385422&sid=1787560585&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1480 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=zi3oh3g526d0)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=zi3oh3g526d0)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3810 ms._
**Document:**
- Lang: lv-LV
- Title: Ziņas - Sorainen
- Canonical: https://www.sorainen.com/lv/zinas/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 133561
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
- en → https://www.sorainen.com/newsroom/
- et → https://www.sorainen.com/et/uudised/
- lv → https://www.sorainen.com/lv/zinas/
- lt → https://www.sorainen.com/lt/naujienos/
- x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Nekas netika atrasts
- h3: Palīdzam privātajiem klientiem aizsargāt un vairot kapitālu: Chambers reitingā S
- h3: Sorainen publicē Ilgtspējas ziņojumu 2026: atbildīga izaugsme un disciplinēts pr
- h3: iFinanses.lv: Kādos autopārvadājumos no 1. jūlija nepieciešams tahogrāfs?
- h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
- h3: Sorainen kļūst par “Liepāja 2027” juridisko partneri ceļā uz Eiropas kultūras ga
- h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
- h3: Sorainen ir atzīts par Gada advokātu biroju Baltijā Chambers Europe 2026 apbalvo
- h3: Sorainen kļūst par Latvijas E‑komercijas Asociācijas sadarbības partneri
- h3: Sorainen turpina atbalstīt Rīgas Juridiskās augstskolas bibliotēku
- h3: Baltijas gada darījumi 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCap
- h3: Piesakieties jaunumiem!
- h3: Meklēt ziņas
- h3: Atslēgvārds
- h3: Sektors
- h3: Pakalpojums
- h3: Valsts
- h3: Datums
- h3: Datums
- h4: Vai jūs interesē juridiskie jaunumi reģionā?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 46 total — 1 defer, 6 async, 17 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0h1 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
**Stylesheets:** 5 external, 5 inline (27.0 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 73 anchors — 7 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×5
- "ziņas" ×3
- "sorainen" ×2
- "specializācija" ×2
- "komanda" ×2
- "karjera" ×2
- "par mums" ×2
- "kontakti" ×2
- "augustas klezys" ×2
- "piret jesse" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 5 of 5 — https://www.sorainen.com/lt/naujienos
Run: 2026-08-24T08:36:35.532Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no
## PageSpeed Insights
_Captured in 13736 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **75** | 97 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.7 s** / 1369 ms p75 (fast) | 1.0 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.004** / 0 p75 (fast) |
| TBT | **68 ms** | 41 ms |
| FCP | **2.99 s** / 1190 ms p75 (fast) | 788 ms / 948 ms p75 (fast) |
| Speed Index | **4.75 s** | 1.37 s |
| TTFB | 2 ms / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |
### Priority fixes
1. **largest-contentful-paint** (high) — 4.7 s
2. **first-contentful-paint** (medium) — 3.0 s
3. **speed-index** (medium) — 4.7 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 410 ms
### Findings (mobile)
#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted
#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 — 84 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 83 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 69 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 57 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 51 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 50 ms
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`
#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.32, weight 25) — Largest Contentful Paint — 4.7 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.50, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.68, weight 10) — Speed Index — 4.7 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.18, weight 0) — Time to Interactive — 11.5 s
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 966 ms._
**Transport:**
- Final URL: https://www.sorainen.com/lt/naujienos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:36 GMT
- expires: Mon, 24 Aug 2026 08:36:35 GMT
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: gzip
- content-length: 19735
- Decoded body: 79.5 KB
- Compression ratio: 0.243
### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS
### Findings
#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Info disclosure
- Server: `Apache / ZoneOS`
#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19735
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:35 GMT
expires: Mon, 24 Aug 2026 08:36:35 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:36 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1604 ms._
**Scoring:** 11 errors · 10 warnings · 81 cosmetic (suppressed)
### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-finansai-ir-draudimas”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-draudimas”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-kapitalo-rinkos”.** (medium) — x1, first at line 358
### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
<script type="text/javascript">
(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/lt/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""plac`
- (×1) [error] Duplicate ID “select-finansai-ir-draudimas”. — first at line 358 `a</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [warning] The first occurrence of ID “select-finansai-ir-draudimas” was here. — first at line 358 `s</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [error] Duplicate ID “select-draudimas”. — first at line 358 `s</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [warning] The first occurrence of ID “select-draudimas” was here. — first at line 358 `ė</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [error] Duplicate ID “select-kapitalo-rinkos”. — first at line 358 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [warning] The first occurrence of ID “select-kapitalo-rinkos” was here. — first at line 358 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas-ir-statyba”. — first at line 358 `i</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas-ir-statyba” was here. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas”. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas” was here. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [error] Duplicate ID “select-statyba”. — first at line 358 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [warning] The first occurrence of ID “select-statyba” was here. — first at line 358 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 458 `m>
</div>
</p>
<`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">Nėra r`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 3674 ms._
**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0
### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label
### Findings
#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-115923 > a`
- `#menu-item-5498 > a`
- `a[aria-current="page"]`
- `#menu-item-115926 > a`
- `#menu-item-5501 > a`
- … and 5 more nodes
#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`
#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`
#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`
#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes
#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 3690 ms._
**Capture summary:** 8 console events · 0 mixed-content requests · 64 network requests · 1.65 MB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 26 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.3 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 798 B |
| ping | 1 | 0 B |
**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B
**Slowest requests (top 5):**
- https://www.sorainen.com/lt/naujienos/ (document) — 518 ms, 19.3 KB
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lt&order=DESC&orderby=date¤tPage=2 (xhr) — 500 ms, 3.1 KB
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/refill (fetch) — 375 ms, 2 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/feedback/schema (fetch) — 374 ms, 752 B
- https://www.sorainen.com/lt/naujienos (document) — 345 ms, 0 B
### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560596477&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1180174349&_eu=AAAAAGAC&are=1&cid=612219591.1787560597&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315471~120385422&sid=1787560596&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1392 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
### Findings
#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ>m=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560596477&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1180174349&_eu=AAAAAGAC&are=1&cid=612219591.1787560597&ec_mode=a&frm=0>m_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315471~120385422&sid=1787560596&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1392 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED
#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=gfbxgblu4con)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=gfbxgblu4con)
- [warning] Couldn't load preload assets: ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 3690 ms._
**Document:**
- Lang: lt-LT
- Title: Naujienos - Sorainen
- Canonical: https://www.sorainen.com/lt/naujienos/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 134783
**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
- en → https://www.sorainen.com/newsroom/
- et → https://www.sorainen.com/et/uudised/
- lv → https://www.sorainen.com/lv/zinas/
- lt → https://www.sorainen.com/lt/naujienos/
- x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
- h2: Nėra rezultatų
- h3: Privatiems klientams padedame apsaugoti, auginti ir perduoti turtą ateities kart
- h3: Mokesčių naujienos: 2026 m. antrasis ketvirtis
- h3: „Sorainen“ paskelbė 2026 m. tvarumo ataskaitą: atsakingas augimas per kryptingą
- h3: „Sorainen“ jau rekordinį dešimtą kartą pripažinta IFLR Baltijos metų teisės firm
- h3: „Sorainen“ pripažinta Baltijos šalių metų teisės firma „Chambers Europe“ 2026 m.
- h3: Stipriname ginčų ir ESG kompetencijas: prie komandos jungiasi advokatė Renata Ja
- h3: 2026 metų Baltijos sandoriai: „Salling Group“, „Tele2“ / „Manulife“, „nexos.ai“,
- h3: „Sorainen“ reikšmingai stiprina savo komandą: daugiausiai partnerių ir stipriaus
- h3: „Sorainen“ paskyrė tris naujus partnerius
- h3: Mūsų komanda pelnė pirmas pozicijas „Chambers FinTech 2026“ reitinguose visose B
- h3: Užsisakykite mūsų naujienlaiškį!
- h3: Ieškoti naujienų
- h3: Raktiniai žodžiai
- h3: Sektorius
- h3: Paslauga
- h3: Šalis
- h3: Data
- h3: Data
- h4: Domina aktualios verslo teisės naujienos?
**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**
**Scripts:** 47 total — 1 defer, 6 async, 17 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c>m=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
**Stylesheets:** 5 external, 5 inline (27.0 KB)
**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
**Links:** 88 anchors — 7 external, 0 preconnect, 0 preload.
Vague repeated link text:
- "eva berlaus" ×5
- "naujienos" ×3
- "saulė dagilytė" ×3
- "dr mindaugas lukas" ×3
- "sorainen" ×2
- "paslaugos" ×2
- "komanda" ×2
- "karjera" ×2
- "apie mus" ×2
- "kontaktai" ×2
**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**
### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
- `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
- `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
- `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`
### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).