Audit

20260824T083556Z-869b

← Back to sorainencom
Audited URL
https://www.sorainen.com/et/
Timestamp
2026-08-24T08:42:04.594Z
Kind
site
Pages
5
Audit summary
https://www.sorainen.com/et/
5 of 5 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

66
Overall site quality
Needs Improvementhigh confidence

Site overall 66 is the mean of 5 pages. Scores range 62 (https://www.sorainen.com/et) → 70 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.

Per-page scores
62
/et
high
62
/newsroom
high
68
/et/uudised
high
70
/lv/zinas
high
68
/lt/naujienos
high

Audit Report: Advokaadibüroo Sorainen

Website: https://www.sorainen.com/et/
Date: 24.08.2026
Audit Coverage: 100% — all sources returned data
Confidence: high

Pages Audited (5 of 5):

Summary of results

Overall Score: 66 / 100
Status: 🟡 Needs Improvement

Site overall 66 is the mean of 5 pages. Scores range 62 (https://www.sorainen.com/et) → 70 (https://www.sorainen.com/lv/zinas). Weakest page: Mobile performance is critically low (52) with an LCP of 10.2 s, driven by 15 render-blocking scripts and heavy third-party JS. Accessibility has critical gaps (12 missing alt attributes) despite a decent 88 score. Security is weak (40/100) with a permissive CSP on a site that hosts user content, elevating XSS risk. Desktop performance (96) is strong, but mobile-first indexing penalizes the mobile experience significantly.

Per-page scores

🟡 Needs Improvement · https://www.sorainen.com/et

Score Performance Accessibility Best Practices SEO Security
62 52 88 92 92 40

🟡 Needs Improvement · https://www.sorainen.com/newsroom

Score Performance Accessibility Best Practices SEO Security
62 58 94 92 85 40

🟡 Needs Improvement · https://www.sorainen.com/et/uudised

Score Performance Accessibility Best Practices SEO Security
68 72 94 92 92 40

🟡 Needs Improvement · https://www.sorainen.com/lv/zinas

Score Performance Accessibility Best Practices SEO Security
70 78 94 92 92 40

🟡 Needs Improvement · https://www.sorainen.com/lt/naujienos

Score Performance Accessibility Best Practices SEO Security
68 75 94 92 92 40

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://www.sorainen.com/et 52 / 86 10.16 s / 2.12 s 0.000 / 0.007
https://www.sorainen.com/newsroom 58 / 93 11.27 s / 1.22 s 0.000 / 0.000
https://www.sorainen.com/et/uudised 72 / 93 5.19 s / 1.10 s 0.000 / 0.006
https://www.sorainen.com/lv/zinas 78 / 93 4.06 s / 1.05 s 0.000 / 0.001
https://www.sorainen.com/lt/naujienos 75 / 97 4.71 s / 1.05 s 0.000 / 0.004

Optimization Checklist

1 of 3 passing — 1 pass · 1 warn · 1 fail · 4 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket)
Images lazy-loaded N/A No raster <img> elements found (4 SVGs excluded).
Hero image eagerly loaded N/A No raster <img> elements found (4 SVGs excluded).
Hero is a real <img> (not a CSS background-image) Warn Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.
Responsive images (srcset / <picture>) N/A Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Fail 3 render-blocking scripts in <head>. Move to footer or add defer/async.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Eliminate render-blocking JavaScript and optimize LCP Performance

  • Impact: LCP (10.2 s), FCP (3.1 s), TBT (466 ms)
  • Problem: 15 render-blocking scripts and heavy third-party JS (Recaptcha, GTM) delay rendering; LCP is 10.2 s on mobile.
  • Solution:
    • Move non-critical scripts to footer or add defer/async.
    • Defer Recaptcha until user interaction (e.g., form focus).
    • Convert hero CSS background to <img> with fetchpriority="high" and srcset.

1B. Add alt text to all content images Accessibility

  • Impact: WCAG 1.1.1 (Non-text Content), SEO
  • Problem: 12 images lack alt attributes (W3C + axe-core critical violations), blocking screen reader users.
  • Solution:
    • Audit all <img> tags.
    • Add descriptive alt text for content images.
    • Use alt="" for purely decorative images (e.g., icons, lines).

1C. Harden CSP and HSTS for User-Generated Content Security

  • Impact: XSS protection, Transport security
  • Problem: Site has user content (hasUserContent: yes) but CSP allows unsafe-inline/unsafe-eval; HSTS missing includeSubDomains.
  • Solution:
    • Remove 'unsafe-inline' and 'unsafe-eval' from CSP; use nonces/hashes for scripts.
    • Update HSTS: Strict-Transport-Security: max-age=63072000; includeSubDomains; preload.

1D. Defer non-critical JavaScript to fix LCP Performance

  • Impact: LCP, FCP, TBT
  • Problem: LCP is 11.3 s on mobile; 17 render-blocking scripts and 1.08 MB of JS (reCAPTCHA, GTM) delay rendering.
  • Solution: Add defer or async to non-critical scripts in <head>. Specifically defer gtag.js, gtm.js, and recaptcha__en.js until after DOMContentLoaded.
    <script src=".../gtag.js" async></script>
    <script src=".../recaptcha__en.js" defer></script>
    

1E. Add accessible labels to forms and buttons Accessibility

  • Impact: WCAG 2.1.1, 4.1.2
  • Problem: 3 critical axe violations: buttons lack discernible text, form inputs (search, select) lack labels.
  • Solution: Associate <label> elements with inputs via for/id. Add aria-label to icon-only buttons.
    <label for="search-text">Search</label>
    <input id="search-text" ...>
    <button aria-label="Close modal">X</button>
    

1F. Harden Content Security Policy (CSP) Security

  • Impact: XSS protection
  • Problem: Site has user-generated content signals, but CSP allows unsafe-inline and unsafe-eval, negating XSS defense.
  • Solution: Remove unsafe-inline and unsafe-eval from script-src. Use nonces or hashes for inline scripts.
    Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
    

1G. Defer render-blocking scripts to improve LCP Performance

  • Impact: LCP (5.2 s), FCP (2.97 s), Speed Index (4.83 s)
  • Problem: 17 render-blocking external scripts found in HTML inventory; LCP is 5.2 s on mobile (heavy penalty >4 s).
  • Solution: Add defer or async to non-critical scripts in <head>. Move analytics and third-party widgets to footer.
    <script src="..." defer></script>
    

1H. Fix critical form and button accessibility violations Accessibility

  • Impact: WCAG 2.1 Level A (button-name, label, select-name)
  • Problem: 3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.
  • Solution:
    • Add aria-label or visible text to filter buttons.
    • Associate <label> elements with inputs using for/id.
    • Add aria-label to <select> elements if visual label is missing.

1I. Harden Content Security Policy (CSP) for UGC Security

  • Impact: XSS protection, Security Headers Grade (40/100)
  • Problem: CSP allows unsafe-inline and unsafe-eval scripts. Site signals indicate User-Generated Content (UGC) exists, raising XSS risk.
  • Solution: Remove 'unsafe-inline' and 'unsafe-eval' from script-src. Implement nonce-based CSP:
    Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
    

1J. Defer render-blocking JavaScript to improve LCP Performance

  • Impact: LCP, FCP, Speed Index
  • Problem: LCP is 4.1 s on mobile; 17 render-blocking scripts identified including jQuery, GTM, and CookieYes.
  • Solution: Add defer or async to non-critical scripts in <head>. Move jQuery and analytics to footer or load after interaction.
    <script src="..." defer></script>
    

1K. Fix critical button and form label violations Accessibility

  • Impact: WCAG 2.1.1, 4.1.2
  • Problem: 3 critical axe violations: filter buttons lack discernible text; search/select elements lack labels.
  • Solution: Add aria-label to icon buttons and associate <label> elements with form inputs.
    <button aria-label="Filter posts">...</button>
    <label for="search">Search</label>
    <input id="search" ...>
    

1L. Eliminate render-blocking JavaScript Performance

  • Impact: LCP, FCP, Speed Index
  • Problem: 17 render-blocking scripts found in <head>; LCP is 4.7 s on mobile (target ≤2.5 s).
  • Solution: Add defer or async to non-critical scripts. Move analytics and third-party tags to footer.
    <script src="..." defer></script>
    

1M. Fix critical form and button labels Accessibility

  • Impact: WCAG 2.4.4, 4.1.2
  • Problem: 3 critical axe violations: buttons lack discernible text, form elements lack labels, select elements lack accessible names.
  • Solution: Add aria-label or visible text to filter buttons and search inputs.
    <button aria-label="Apply filters">Apply</button>
    <input aria-label="Search" type="text">
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Fix contrast, labels, and landmarks Accessibility

  • Impact: WCAG 1.4.3 (Contrast), 2.4.1 (Bypass Blocks)
  • Problem: Menu links fail contrast; search fields lack labels; no main landmark or skip-link.
  • Solution:
    • Increase text contrast to ≥4.5:1.
    • Add <label> or aria-label to search inputs.
    • Add <main> tag and a 'Skip to content' link at the top.

2B. Add H1 and Meta Description SEO

  • Impact: Search ranking, CTR
  • Problem: W3C reports 0 H1 elements; SEO audit flags missing meta description.
  • Solution: Ensure exactly one <h1> per page reflecting the main topic. Add <meta name="description" content="..."> summarizing the newsroom content.

2C. Complete HSTS Configuration Security

  • Impact: Transport security
  • Problem: HSTS header present but missing includeSubDomains and preload directives.
  • Solution: Update server config to include subdomains and preload flag.
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    

2D. Add a single H1 element to the page SEO

  • Impact: Document outline, Search ranking
  • Problem: HTML inventory shows 0 H1 elements; page starts with H2. W3C validator notes heading structure issues.
  • Solution: Ensure the main page title is wrapped in a single <h1> tag at the top of the content flow.
    <h1>Videod - Sorainen</h1>
    

2E. Fix HTML validation errors and duplicate IDs Best Practices

  • Impact: Code quality, Rendering consistency
  • Problem: W3C validator reports 7 errors including duplicate ID 'select-kapitaliturud' and malformed attributes (e.g., 'stylr').
  • Solution:
    • Ensure all IDs are unique.
    • Correct attribute typos (e.g., stylr → style).
    • Fix empty href attributes on <link> elements.

2F. Add a unique H1 heading SEO

  • Impact: Document outline, Search ranking
  • Problem: HTML Inventory confirms 0 <h1> elements; W3C notes no heading level 1.
  • Solution: Ensure the page title is wrapped in a single <h1> tag at the top of the main content.
    <h1>Ziņas</h1>
    

2G. Harden HSTS and review CSP Security

  • Impact: Transport security, XSS defense
  • Problem: HSTS missing includeSubDomains; CSP allows unsafe-inline and unsafe-eval.
  • Solution: Update HSTS header to include subdomains. For CSP, remove unsafe-inline where possible or use nonces.
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

2H. Strengthen HSTS header Security

  • Impact: Transport security, downgrade attacks
  • Problem: HSTS present but missing includeSubDomains and preload directives (Grade 40/100).
  • Solution: Update server config to include subdomains and preload flag.
    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

2I. Add H1 and Main landmark SEO

  • Impact: Document outline, Screen readers
  • Problem: 0 <h1> elements and missing <main> landmark detected in HTML inventory.
  • Solution: Ensure exactly one <h1> per page and wrap primary content in <main>.
    <h1>Naujienos</h1>
    <main>...</main>
    

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Reduce image weight and add dimensions Performance

  • Impact: CLS, Page Weight (2.67 MB)
  • Problem: 16 images missing width/height attributes; 19 images missing lazy loading.
  • Solution:
    • Add width and height attributes to all <img> tags.
    • Ensure loading="lazy" is present on off-screen images.
    • Convert remaining PNG/JPEG to WebP/AVIF.

3B. Fix HTML validation errors Best Practices

  • Impact: Code quality, Rendering consistency
  • Problem: W3C reports 11 errors including duplicate IDs and invalid attributes (e.g., stylr).
  • Solution: Audit the HTML source for duplicate id attributes and correct typos in attribute names. Ensure unique IDs for form elements.

3C. Harden Content Security Policy Security

  • Impact: XSS defense-in-depth
  • Problem: CSP allows unsafe-inline and unsafe-eval, which bypasses XSS protections.
  • Solution: Replace unsafe-inline with nonce/hash strategy for scripts and styles.
    Content-Security-Policy: script-src 'nonce-{random}' 'strict-dynamic';
    
▸Raw Markdown sent to the LLM
# Site Audit — https://www.sorainen.com/et/
Run: 2026-08-24T08:35:56.367Z

Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://www.sorainen.com/et
- https://www.sorainen.com/newsroom
- https://www.sorainen.com/et/uudised
- https://www.sorainen.com/lv/zinas
- https://www.sorainen.com/lt/naujienos

---

# Page 1 of 5 — https://www.sorainen.com/et

Run: 2026-08-24T08:36:01.013Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 22977 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **52** | 86 |
| Accessibility | 88 | **84** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **10.2 s** / 1369 ms p75 (fast) | 2.1 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.007** / 0 p75 (fast) |
| TBT | **466 ms** | 45 ms |
| FCP | **3.10 s** / 1190 ms p75 (fast) | 833 ms / 948 ms p75 (fast) |
| Speed Index | **6.33 s** | 1.85 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 10.2 s
2. **total-blocking-time** (medium) — 470 ms
3. **speed-index** (high) — 6.3 s
4. **first-contentful-paint** (high) — 3.1 s
5. **cache-insight** (medium) — Est savings of 2 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 152 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 72 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 38 KB wasted

#### Long tasks
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 212 ms
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 195 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 172 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 131 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 129 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 110 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 90 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 77 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 73 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 66 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 10.2 s
- `total-blocking-time` (performance, score 0.61, weight 30) — Total Blocking Time — 470 ms
- `image-alt` (accessibility, score 0.00, weight 10) — Image elements do not have `[alt]` attributes
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `target-size` (accessibility, score 0.00, weight 7) — Touch targets do not have sufficient size or spacing.
- `speed-index` (performance, score 0.41, weight 10) — Speed Index — 6.3 s
- `first-contentful-paint` (performance, score 0.46, weight 10) — First Contentful Paint — 3.1 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `image-alt` (seo, score 0.00, weight 1) — Image elements do not have `[alt]` attributes
- `interactive` (performance, score 0.08, weight 0) — Time to Interactive — 14.8 s
- `max-potential-fid` (performance, score 0.62, weight 0) — Max Potential First Input Delay — 210 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 380 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:29:08 GMT
- expires: Mon, 24 Aug 2026 08:36:01 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 15820
- Decoded body: 67.4 KB
- Compression ratio: 0.229

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 15820
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:01 GMT
expires: Mon, 24 Aug 2026 08:36:01 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:29:08 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1328 ms._

**Scoring:** 16 errors · 5 warnings · 40 cosmetic (suppressed)

> **Validator truncated at line 412** — the Nu validator stopped after hitting its internal error budget; score against the errors above, NOT as a fatal parse failure: Cannot recover after last error. Any further errors will be ignored.

### Priority fixes
1. **Parser recovery at line 412** (high) — Cannot recover after last error. Any further errors will be ignored.
2. **An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images.** (high) — x12, first at line 260
3. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 59
4. **Start tag “a” seen but an element of the same type was already open.** (medium) — x1, first at line 412
5. **End tag “a” violates nesting rules.** (medium) — x1, first at line 412

### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 59 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 104 `33;" />
		<script type="text/javascript">
			(f`
- (×12) [error] An “img” element must have an “alt” attribute, except under certain conditions. For details, consult guidance on providing text alternatives for images. — first at line 260 `<img src="https://www.sorainen.com/wp-content/themes/sorainen/build/img/line__ho`
- (×2) [warning] Empty heading. — first at line 277 `<h2></h2>`
- (×1) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 339 `<section class="homePeople bg-purple">
			<d`
- (×1) [error] Start tag “a” seen but an element of the same type was already open. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`
- (×1) [error] End tag “a” violates nesting rules. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`
- (×1) [error] Cannot recover after last error. Any further errors will be ignored. — first at line 412 `uthor"> / <a href="https://www.sorainen.com/et/inimesed/kaido-kunnapas/">Dr Kai`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 4297 ms._

**Scoring:** 7 violations · 51 passes · critical 2 · serious 3 · moderate 1 · minor 1

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **image-alt** (high) — Images must have alternative text
3. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
4. **label-title-only** (high) — Form elements should have a visible label
5. **link-name** (high) — Links must have discernible text

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.headerSearch__toggle.col-tp-none.col-m-none`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `.current_page_parent > a`
- … and 5 more nodes

#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `#slick-slide00 > a[target="_self"] > .homeHeroSlider__main > h2`

#### `image-alt` (critical) — WCAG: wcag2a, wcag111
[Images must have alternative text](https://dequeuniversity.com/rules/axe/4.11/image-alt?application=playwright)
- `.homeHero__line1`
- `.homeHero__line2`
- `.line__homePeople_1`
- `.line__homePeople_2`
- `.line__homePeople_3`
- … and 3 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.searchBar > .container > .btn-close.btn[href="javascript:;"]`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`
- … and 1 more nodes

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `h1`
- `.homeHero__line1`
- `.homeHero__quote`
- … and 20 more nodes

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 4314 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 77 network requests · 2.67 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 27 | 1.12 MB |
| script | 23 | 1.04 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| document | 3 | 15.4 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |
| xhr | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 573 ms, 138.5 KB
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (script) — 556 ms, 312.4 KB
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (script) — 549 ms, 862 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 485 ms, 668 B
- https://www.sorainen.com/et (document) — 482 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561664&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=835472063&_eu=AAAAAGAC&are=1&cid=1130938773.1787560563&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938469~118012008~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1437 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561664&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=835472063&_eu=AAAAAGAC&are=1&cid=1130938773.1787560563&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=7&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938469~118012008~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2F&dt=Advokaadib%C3%BCroo%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1437 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=htbdv9zge3vz)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=htbdv9zge3vz)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 4314 ms._

**Document:**
- Lang: et
- Title: Advokaadibüroo Sorainen
- Canonical: https://www.sorainen.com/et/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 112224

**Meta tags:**
- Description: Oleme äriõigusele keskendunud regionaalne advokaadibüroo, kus Eesti, Läti ja Leedu kontorid tegutsevad ühtse tervikuna.
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 10 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://www.sorainen.com/
  - et → https://www.sorainen.com/et/
  - lv → https://www.sorainen.com/lv/
  - lt → https://www.sorainen.com/lt/
  - x-default → https://www.sorainen.com/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×6, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Aitame klientidel olla äris edukad
  - h2: 
  - h2: 
  - h2: Eesti edu võti on kiirus ja vägevad põlvkonnad
  - h2: Meiega liitus Eesti tuntumaid ja kogenumaid tehingunõustajaid Sven Papp
  - h2: Värsked edetabelid kinnitavad meie positsiooni Baltikumi tippbüroona
  - h2: Nõustamisvaldkonnad
  - h3: Eva Berlaus, juhtivpartner
  - h3: Eva Berlaus, juhtivpartner
  - h2: Uudised
  - h3: Maksu-uudised: millal tuleb Eestis käibemaksukohustuslasena registreeruda ja kui
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 40 total — 1 defer, 5 async, 15 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0

**Stylesheets:** 5 external, 6 inline (27.1 KB)

**Images:** 21 total — **12 without alt**, **16 without width/height**, 19 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| om/wp-content/themes/sorainen/build/img/line__homeHero_2.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| ent/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif | _(empty)_ | 1142×1243 | _n/a_ | ✗ |
| wp-content/uploads/2025/11/new-horizons-with-sorainen-ee.png | Tekst: „Koos jõuame kaugemale – aitame e | 1142×1243 | _n/a_ | ✓ |
| uploads/2026/07/soraineni-sagedus-edukas-eesti-thumbnail.png | Soraineni Sagedus Edukas Eesti Kaupo Lep | 1080×1080 | _n/a_ | ✓ |
| m/wp-content/uploads/2026/04/sven-papp-ee-web-front-page.png | Ühinemiste ja ülevõtmiste, ühingu- ja tö | 1142×1243 | lazy | ✓ |
| nd-legal-500-2026-campaign-web-first-page-1142-x-1243-px.png | Top tier firm. Legal500. Chambers top ra | 1142×1243 | lazy | ✓ |
| wp-content/themes/sorainen/build/img/line__homeHero_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| /wp-content/themes/sorainen/build/img/line__homePeople_1.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/line__homePeople_1--m.svg | _(no attr)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 71 anchors — 8 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "nõustamisvaldkonnad" ×5
- "uudised" ×3
- "sorainen" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "näita kõiki uudiseid" ×2
- "dr kaido künnapas" ×2
- "elisabeth lauri" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- search — **no label**
Form 3:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
2. **12 images without alt attribute** (high) — Content images need descriptive alt text; decorative images need empty alt=""
3. **16 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **15 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 5 pass · 1 warn · 1 fail

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | ✓ pass | All raster images use loading="lazy" (16 SVGs excluded). |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | ! warn | Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/5 raster images use srcset or <picture> (80%) (16 SVGs excluded). |
| Reasonable number of image sizes | ✓ pass | 11 distinct srcset widths. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- Hero image eagerly loaded:
  - `hero: …ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
  - `loading: (not set)`
  - `fetchpriority: high`
- Hero is a real <img> (not a CSS background-image):
  - `selector: div.expertiseIntro__img.bg-cover`
  - `url: ….sorainen.com/wp-content/uploads/2026/05/eva-berlaus-sorainen-2026-scaled.jpg`
  - `box: 419×624px`
- Responsive images (srcset / <picture>):
  - `…ainen.com/wp-content/uploads/2026/07/newsletter-subscription-2026-ee-hero.gif`
- Reasonable number of image sizes:
  - `widths: 46, 50, 150, 240, 310, 500, 541, 589, 768, 1080, 1142`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.
2. **Hero is a real <img> (not a CSS background-image)** (medium) — Hero element uses a CSS background-image (no image-set() variants), so the browser always loads the original asset regardless of viewport — there is no srcset equivalent. Move the hero to a real <img> with srcset/sizes (or <picture>) so smaller viewports can fetch a smaller file.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 5 — https://www.sorainen.com/newsroom

Run: 2026-08-24T08:36:01.015Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 19112 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **58** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 85 | 85 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **11.3 s** / 1369 ms p75 (fast) | 1.2 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.000** / 0 p75 (fast) |
| TBT | **356 ms** | 127 ms |
| FCP | **3.05 s** / 1190 ms p75 (fast) | 790 ms / 948 ms p75 (fast) |
| Speed Index | **5.04 s** | 1.45 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 11.3 s
2. **total-blocking-time** (medium) — 360 ms
3. **first-contentful-paint** (high) — 3.0 s
4. **speed-index** (medium) — 5.0 s
5. **cache-insight** (medium) — Est savings of 2 KiB

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 166 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 133 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 124 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 83 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 80 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 80 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 71 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 57 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 53 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.00, weight 25) — Largest Contentful Paint — 11.3 s
- `total-blocking-time` (performance, score 0.72, weight 30) — Total Blocking Time — 360 ms
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.63, weight 10) — Speed Index — 5.0 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `link-text` (seo, score 0.00, weight 1) — Links do not have descriptive text — 1 link found
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 11.9 s
- `max-potential-fid` (performance, score 0.78, weight 0) — Max Potential First Input Delay — 170 ms

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 397 ms._

**Transport:**
- Final URL: https://www.sorainen.com/newsroom/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:31:13 GMT
- expires: Mon, 24 Aug 2026 08:36:01 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 18550
- Decoded body: 77.3 KB
- Compression ratio: 0.234

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Keep-Alive
content-encoding: gzip
content-length: 18550
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:01 GMT
expires: Mon, 24 Aug 2026 08:36:01 GMT
keep-alive: timeout=5, max=94
last-modified: Mon, 24 Aug 2026 08:31:13 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1397 ms._

**Scoring:** 9 errors · 8 warnings · 81 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-50-8002b801-adc4a003”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-insurance”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-50-8002b801-adc4a006”.** (medium) — x1, first at line 358

### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/newsletter/" class="btn btn-primary btn-primar`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a003”. — first at line 358 `s</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a003” was here. — first at line 358 `g</option><option id="select-50-8002b801-adc4a003" value="50-8002b801-adc4a003" `
- (×1) [error] Duplicate ID “select-insurance”. — first at line 358 `s</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [warning] The first occurrence of ID “select-insurance” was here. — first at line 358 `t</option><option id="select-insurance" value="insurance" data-name=" - Insuranc`
- (×1) [error] Duplicate ID “select-50-8002b801-adc4a006”. — first at line 358 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-adc4a006” was here. — first at line 358 `n</option><option id="select-50-8002b801-adc4a006" value="50-8002b801-adc4a006" `
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c0d”. — first at line 358 `l</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c0d” was here. — first at line 358 `n</option><option id="select-50-8002b801-ae3c5c0d" value="50-8002b801-ae3c5c0d" `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 454 `m>
</div>
</p>
    <`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">No res`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 4294 ms._

**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5479 > a`
- `#menu-item-5480 > a`
- `#menu-item-24447 > a`
- `#menu-item-104922 > a`
- `#menu-item-5483 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [Links must be distinguishable without relying on color](https://dequeuniversity.com/rules/axe/4.11/link-in-text-block?application=playwright) — 1 node
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 4307 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 1.64 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 25 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 18.1 KB |
| xhr | 2 | 2.7 KB |
| fetch | 8 | 709 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/feedback/schema (fetch) — 543 ms, 663 B
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=en&order=DESC&orderby=date&currentPage=2 (xhr) — 537 ms, 2.7 KB
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 (script) — 495 ms, 190.1 KB
- https://www.sorainen.com/wp-json/contact-form-7/v1/contact-forms/4/refill (fetch) — 434 ms, 2 B
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (script) — 380 ms, 138.6 KB

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561590&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=549162681&_eu=AAAAAGAC&are=1&cid=1661390690.1787560563&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938465~115938469~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1677 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560561590&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=549162681&_eu=AAAAAGAC&are=1&cid=1661390690.1787560563&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=4&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938465~115938469~118897920~118897930~119367802~119367810~120213116~120315471~120385423&sid=1787560562&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fnewsroom%2F&dt=Newsroom%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1677 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ip11q44w94xf)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=ip11q44w94xf)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 4307 ms._

**Document:**
- Lang: en-US
- Title: Newsroom - Sorainen
- Canonical: https://www.sorainen.com/newsroom/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 132050

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://www.sorainen.com/newsroom/
  - et → https://www.sorainen.com/et/uudised/
  - lv → https://www.sorainen.com/lv/zinas/
  - lt → https://www.sorainen.com/lt/naujienos/
  - x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: No results
  - h3: Helping Baltic private clients protect, grow and pass on their wealth: Sorainen 
  - h3: Sorainen receives “Supporter of national defence” recognition for the fourth con
  - h3: Sorainen publishes Sustainability Report 2026: responsible growth through discip
  - h3: Key ESG developments across the EU and the Baltics: Q2 2026 update
  - h3: Sorainen awarded IFLR Baltic Law Firm of the Year 2026 for record 10th time for 
  - h3: The Baltic M&A and Private Equity Forum: Bigger than the Baltics – ambition, exe
  - h3: Sorainen awarded Baltic Law Firm of the Year at the Chambers Europe 2026 ceremon
  - h3: Sorainen arbitration team repeatedly ranked in GAR 100 2026
  - h3: We strengthen Dispute Resolution and ESG capabilities with the addition of attor
  - h3: Baltic Deals of the Year 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Join our newsletter!
  - h3: Search news
  - h3: Keyword
  - h3: Sector
  - h3: Service
  - h3: Country
  - h3: Date
  - h3: Date
  - h4: Interested in legal updates on business law in the region?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 44 total — 1 defer, 5 async, 17 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0

**Stylesheets:** 5 external, 6 inline (27.1 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 93 anchors — 7 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×6
- "sorainen" ×2
- "expertise" ×2
- "people" ×2
- "newsroom" ×2
- "careers" ×2
- "about us" ×2
- "contacts" ×2
- "saulė dagilytė" ×2
- "laimonas skibarka" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
3. **17 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 5 — https://www.sorainen.com/et/uudised

Run: 2026-08-24T08:36:20.128Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "post"
- E-commerce: no

## PageSpeed Insights
_Captured in 15404 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **72** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **5.2 s** / 1369 ms p75 (fast) | 1.1 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.006** / 0 p75 (fast) |
| TBT | 79 ms | **163 ms** |
| FCP | **2.97 s** / 1190 ms p75 (fast) | 802 ms / 948 ms p75 (fast) |
| Speed Index | **4.83 s** | 1.28 s |
| TTFB | 2 ms / 704 ms p75 (fast) | **3 ms** / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 5.2 s
2. **first-contentful-paint** (medium) — 3.0 s
3. **speed-index** (medium) — 4.8 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 510 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j1h2 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j1h2 — 92 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 79 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 70 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 57 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 55 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.23, weight 25) — Largest Contentful Paint — 5.2 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.51, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.66, weight 10) — Speed Index — 4.8 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.16, weight 0) — Time to Interactive — 11.9 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 877 ms._

**Transport:**
- Final URL: https://www.sorainen.com/et/uudised/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:20 GMT
- expires: Mon, 24 Aug 2026 08:36:20 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19448
- Decoded body: 79.8 KB
- Compression ratio: 0.238

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19448
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:20 GMT
expires: Mon, 24 Aug 2026 08:36:20 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:20 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1252 ms._

**Scoring:** 7 errors · 5 warnings · 84 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 361
2. **Bad value “” for attribute “href” on element “link”: Must be non-empty.** (medium) — x1, first at line 59
3. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 359
4. **Duplicate ID “select-kapitaliturud”.** (medium) — x1, first at line 361
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 461

### Issue groups
- (×1) [error] Bad value “” for attribute “href” on element “link”: Must be non-empty. — first at line 59 `refetch">
<link data-rocket-prefetch href="" rel="dns-prefetch">
<link`
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 100 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 359 `<a href="https://www.sorainen.com/et/uudiskiri/" class="btn btn-primary btn-prim`
- (×3) [error] No space between attributes. — first at line 361 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-kapitaliturud”. — first at line 361 `)</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [warning] The first occurrence of ID “select-kapitaliturud” was here. — first at line 361 `s</option><option id="select-kapitaliturud" value="kapitaliturud" data-name=" - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 461 `m>
</div>
</p>
    <`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 270 `<h2 class="postsEmpty__title">Tulemu`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3731 ms._

**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-11670 > a`
- `#menu-item-5492 > a`
- `#footer-menu > .menu-item-104921.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5495 > a`
- `#footer-menu > .current_page_parent.current_page_parent-type-post_type.current_page_parent-object-page > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3744 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 63 network requests · 1.64 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 25 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.0 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 714 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/et/uudised/ (document) — 509 ms, 19.0 KB
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=et&order=DESC&orderby=date&currentPage=2 (xhr) — 449 ms, 3.1 KB
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/feedback/schema (fetch) — 388 ms, 668 B
- https://www.sorainen.com/et/wp-json/contact-form-7/v1/contact-forms/11613/refill (fetch) — 378 ms, 2 B
- https://www.sorainen.com/et/uudised (document) — 355 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560581066&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1820137604&_eu=AAAAAGAC&are=1&cid=991115098.1787560582&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385423&sid=1787560581&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Videod%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1383 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560581066&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1820137604&_eu=AAAAAGAC&are=1&cid=991115098.1787560582&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=2&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616985~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385423&sid=1787560581&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Fet%2Fuudised%2F&dt=Videod%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&gap.plf=5&ep.debug_mode=true&tfd=1383 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=a1b0czzbyuan)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=a1b0czzbyuan)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3744 ms._

**Document:**
- Lang: et
- Title: Videod - Sorainen
- Canonical: https://www.sorainen.com/et/uudised/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 134850

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://www.sorainen.com/newsroom/
  - et → https://www.sorainen.com/et/uudised/
  - lv → https://www.sorainen.com/lv/zinas/
  - lt → https://www.sorainen.com/lt/naujienos/
  - x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Tulemusi ei leitud
  - h3: Maksu-uudised: millal tuleb Eestis käibemaksukohustuslasena registreeruda ja kui
  - h3: Pälvisime Kaitseministeeriumilt neljandat aastat järjest „Riigikaitsjate toetaja
  - h3: Soraineni jätkusuutlikkuse aruanne 2026: vastutustundlik kasv läbi sihipärase ar
  - h3: Maksu-uudised: millal kaob optsioonide maksuvabastus ja kas Eesti võiks olla USA
  - h3: IFLR nimetas Soraineni kümnendat korda Baltimaade parimaks
  - h3: Kohaliku omavalitsuse uudised: olulised muudatused ehituses, hariduses ja tarist
  - h3: Sorainen valiti Chambers Europe 2026 galal Balti riikide aasta advokaadibürooks
  - h3: Eduka Eesti võitis idee luua Eesti ettevõtete kaitseliit
  - h3: 2026. aasta suurtehingud tegid Salling Group, Tele2 / Manulife, nexos.ai, BaltCa
  - h3: Maksu-uudised: vabatahtlik reserv omakapitali sissemaksena, Eesti maksutahtest j
  - h3: Soovid meie uudiskirju?
  - h3: Otsi uudiseid
  - h3: Märksõna
  - h3: Ärivaldkond
  - h3: Õigusvaldkond
  - h3: Riik
  - h3: Kuupäev
  - h3: Kuupäev
  - h4: Kas soovid saada õigus- ja maksu-uudiseid Baltimaade kohta?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 45 total — 1 defer, 5 async, 17 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0

**Stylesheets:** 5 external, 5 inline (27.0 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 84 anchors — 8 external, 0 preconnect, 1 preload.

Vague repeated link text:
- "eva berlaus" ×4
- "uudised" ×3
- "dr kaido künnapas" ×3
- "sorainen" ×2
- "nõustamisvaldkonnad" ×2
- "inimesed" ×2
- "liitu meiega" ×2
- "meist" ×2
- "kontakt" ×2
- "verner silm" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 5 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 5 — https://www.sorainen.com/lv/zinas

Run: 2026-08-24T08:36:23.990Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 16712 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **78** | 93 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.1 s** / 1369 ms p75 (fast) | 1.0 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.001** / 0 p75 (fast) |
| TBT | 100 ms | **156 ms** |
| FCP | **3.05 s** / 1190 ms p75 (fast) | 817 ms / 948 ms p75 (fast) |
| Speed Index | **4.87 s** | 1.41 s |
| TTFB | **3 ms** / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.1 s
2. **first-contentful-paint** (high) — 3.0 s
3. **speed-index** (medium) — 4.9 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 420 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 152 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 103 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 85 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 80 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 62 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 57 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 51 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js — 50 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.48, weight 25) — Largest Contentful Paint — 4.1 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.48, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.66, weight 10) — Speed Index — 4.9 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.17, weight 0) — Time to Interactive — 11.8 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 852 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lv/zinas/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:24 GMT
- expires: Mon, 24 Aug 2026 08:36:24 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19517
- Decoded body: 79.7 KB
- Compression ratio: 0.239

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19517
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:24 GMT
expires: Mon, 24 Aug 2026 08:36:24 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:24 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1248 ms._

**Scoring:** 11 errors · 10 warnings · 88 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-50-8002b801-ae3c5c07”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-finanses-un-apdrosinasana”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-kapitala-tirgi”.** (medium) — x1, first at line 358

### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/lv/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""placeholder=""`
- (×1) [error] Duplicate ID “select-50-8002b801-ae3c5c07”. — first at line 358 `l</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [warning] The first occurrence of ID “select-50-8002b801-ae3c5c07” was here. — first at line 358 `a</option><option id="select-50-8002b801-ae3c5c07" value="50-8002b801-ae3c5c07" `
- (×1) [error] Duplicate ID “select-finanses-un-apdrosinasana”. — first at line 358 `a</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [warning] The first occurrence of ID “select-finanses-un-apdrosinasana” was here. — first at line 358 `i</option><option id="select-finanses-un-apdrosinasana" value="finanses-un-apdro`
- (×1) [error] Duplicate ID “select-kapitala-tirgi”. — first at line 358 `)</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [warning] The first occurrence of ID “select-kapitala-tirgi” was here. — first at line 358 `a</option><option id="select-kapitala-tirgi" value="kapitala-tirgi" data-name=" `
- (×1) [error] Duplicate ID “select-nekustamais-ipasums-un-buvnieciba”. — first at line 358 `a</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums-un-buvnieciba” was here. — first at line 358 `i</option><option id="select-nekustamais-ipasums-un-buvnieciba" value="nekustama`
- (×1) [error] Duplicate ID “select-buvnieciba”. — first at line 358 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [warning] The first occurrence of ID “select-buvnieciba” was here. — first at line 358 `a</option><option id="select-buvnieciba" value="buvnieciba" data-name=" - Būvnie`
- (×1) [error] Duplicate ID “select-nekustamais-ipasums”. — first at line 358 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [warning] The first occurrence of ID “select-nekustamais-ipasums” was here. — first at line 358 `a</option><option id="select-nekustamais-ipasums" value="nekustamais-ipasums" da`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 457 `m>
</div>
</p>
    <`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">Nekas`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3798 ms._

**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-5485 > a`
- `#menu-item-5486 > a`
- `#menu-item-115921 > a`
- `#footer-menu > .menu-item-104920.menu-item-type-post_type.menu-item-object-page > a`
- `#menu-item-5489 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3810 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 64 network requests · 1.65 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 26 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.1 KB |
| xhr | 2 | 3.0 KB |
| fetch | 8 | 809 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lv&order=DESC&orderby=date&currentPage=2 (xhr) — 484 ms, 3.0 KB
- https://www.sorainen.com/lv/zinas/ (document) — 474 ms, 19.1 KB
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (script) — 425 ms, 312.4 KB
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/refill (fetch) — 401 ms, 2 B
- https://www.sorainen.com/lv/wp-json/contact-form-7/v1/contact-forms/11610/feedback/schema (fetch) — 383 ms, 763 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0h1v898627717z8835828663za20gzb835828663zd835828663&_p=1787560584887&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=485409269&_eu=AAAAAGAC&are=1&cid=354160805.1787560585&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385422&sid=1787560585&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1480 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0h1v898627717z8835828663za20gzb835828663zd835828663&_p=1787560584887&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&gdid=dY2Q2ZW&ecid=485409269&_eu=AAAAAGAC&are=1&cid=354160805.1787560585&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=11&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315470~120385422&sid=1787560585&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flv%2Fzinas%2F&dt=Zi%C5%86as%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1480 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=zi3oh3g526d0)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=zi3oh3g526d0)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3810 ms._

**Document:**
- Lang: lv-LV
- Title: Ziņas - Sorainen
- Canonical: https://www.sorainen.com/lv/zinas/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 133561

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://www.sorainen.com/newsroom/
  - et → https://www.sorainen.com/et/uudised/
  - lv → https://www.sorainen.com/lv/zinas/
  - lt → https://www.sorainen.com/lt/naujienos/
  - x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nekas netika atrasts
  - h3: Palīdzam privātajiem klientiem aizsargāt un vairot kapitālu: Chambers reitingā S
  - h3: Sorainen publicē Ilgtspējas ziņojumu 2026: atbildīga izaugsme un disciplinēts pr
  - h3: iFinanses.lv: Kādos autopārvadājumos no 1. jūlija nepieciešams tahogrāfs?
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen kļūst par “Liepāja 2027” juridisko partneri ceļā uz Eiropas kultūras ga
  - h3: Sorainen jau desmito reizi saņem IFLR balvu “Gada nacionālais advokātu birojs Ba
  - h3: Sorainen ir atzīts par Gada advokātu biroju Baltijā Chambers Europe 2026 apbalvo
  - h3: Sorainen kļūst par Latvijas E‑komercijas Asociācijas sadarbības partneri
  - h3: Sorainen turpina atbalstīt Rīgas Juridiskās augstskolas bibliotēku
  - h3: Baltijas gada darījumi 2026: Salling Group, Tele2 / Manulife, nexos.ai, BaltCap 
  - h3: Piesakieties jaunumiem!
  - h3: Meklēt ziņas
  - h3: Atslēgvārds
  - h3: Sektors
  - h3: Pakalpojums
  - h3: Valsts
  - h3: Datums
  - h3: Datums
  - h4: Vai jūs interesē juridiskie jaunumi reģionā?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 46 total — 1 defer, 6 async, 17 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0h1 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0

**Stylesheets:** 5 external, 5 inline (27.0 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 73 anchors — 7 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "ziņas" ×3
- "sorainen" ×2
- "specializācija" ×2
- "komanda" ×2
- "karjera" ×2
- "par mums" ×2
- "kontakti" ×2
- "augustas klezys" ×2
- "piret jesse" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 5 — https://www.sorainen.com/lt/naujienos

Run: 2026-08-24T08:36:35.532Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: no
- E-commerce: no

## PageSpeed Insights
_Captured in 13736 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **75** | 97 |
| Accessibility | 94 | **82** |
| Best Practices | 92 | 92 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **4.7 s** / 1369 ms p75 (fast) | 1.0 s / 1077 ms p75 (fast) |
| CLS | 0.000 / 0 p75 (fast) | **0.004** / 0 p75 (fast) |
| TBT | **68 ms** | 41 ms |
| FCP | **2.99 s** / 1190 ms p75 (fast) | 788 ms / 948 ms p75 (fast) |
| Speed Index | **4.75 s** | 1.37 s |
| TTFB | 2 ms / 704 ms p75 (fast) | 2 ms / 759 ms p75 (fast) |
| INP (field only) | 83 ms p75 (fast) | 44 ms p75 (fast) |

### Priority fixes
1. **largest-contentful-paint** (high) — 4.7 s
2. **first-contentful-paint** (medium) — 3.0 s
3. **speed-index** (medium) — 4.7 s
4. **cache-insight** (medium) — Est savings of 2 KiB
5. **document-latency-insight** (high) — Est savings of 410 ms

### Findings (mobile)

#### Unused JavaScript
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 158 KB wasted
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 151 KB wasted
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 71 KB wasted
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 56 KB wasted
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802 — 42 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more/build/frontend/ajax-load-more.min.js?ver=8.0.1 — 40 KB wasted
- https://www.sorainen.com/wp-content/plugins/ajax-load-more-filters/dist/js/filters.min.js?ver=3.4.2 — 32 KB wasted

#### Long tasks
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 — 84 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 83 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 69 ms
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js — 57 ms
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 — 51 ms
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js — 50 ms

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
- Best Practices: `errorsInConsole`
- Best Practices: `inspectorIssues`

#### All failing PSI audits (sorted by weight × failure margin)
- `largest-contentful-paint` (performance, score 0.32, weight 25) — Largest Contentful Paint — 4.7 s
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `link-name` (accessibility, score 0.00, weight 7) — Links do not have a discernible name
- `first-contentful-paint` (performance, score 0.50, weight 10) — First Contentful Paint — 3.0 s
- `speed-index` (performance, score 0.68, weight 10) — Speed Index — 4.7 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `errors-in-console` (best-practices, score 0.00, weight 1) — Browser errors were logged to the console
- `inspector-issues` (best-practices, score 0.00, weight 1) — Issues were logged in the `Issues` panel in Chrome Devtools
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
- `interactive` (performance, score 0.18, weight 0) — Time to Interactive — 11.5 s

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 966 ms._

**Transport:**
- Final URL: https://www.sorainen.com/lt/naujienos/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `max-age=0`
- etag: n/a
- last-modified: Mon, 24 Aug 2026 08:36:36 GMT
- expires: Mon, 24 Aug 2026 08:36:35 GMT
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: gzip
- content-length: 19735
- Decoded body: 79.5 KB
- Compression ratio: 0.243

### Priority fixes
1. **strict-transport-security weak** (high) — missing includeSubDomains directive; missing preload directive
2. **content-security-policy weak** (high) — allows unsafe-inline scripts; allows unsafe-eval scripts
3. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
4. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
5. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
6. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
7. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
8. **server header discloses technology** (low) — Server: Apache / ZoneOS

### Findings

#### Tracked headers
- **strict-transport-security** (weak, high) `max-age=31536000` — missing includeSubDomains directive; missing preload directive
- **content-security-policy** (weak, high) `default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'` — allows unsafe-inline scripts; allows unsafe-eval scripts
- **x-frame-options** (present, medium) `SAMEORIGIN`
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Info disclosure
- Server: `Apache / ZoneOS`


#### All response headers
```
cache-control: max-age=0
connection: Upgrade, Keep-Alive
content-encoding: gzip
content-length: 19735
content-security-policy: default-src 'self' https://*.clarity.ms https://c.bing.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://support.play.ee https://snap.licdn.com cdn-cookieyes.com https://cdnjs.cloudflare.com/ajax/libs/cookieconsent2/ *.google-analytics.com https://tagmanager.google.com/ https://www.googletagmanager.com https://beacon-v2.helpscout.net/ https://my.yoast.com https://yoast.com https://connect.facebook.net https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.clarity.ms https://scripts.clarity.ms; style-src 'self' 'unsafe-inline' https://hello.myfonts.net https://tagmanager.google.com/ https://fonts.googleapis.com; img-src 'self' https://claritystatic.blob.core.windows.net https://www.facebook.com https://www.linkedin.com https://www.google.ee *.analytics.google.com https://px.ads.linkedin.com data: cdn-cookieyes.com *.google-analytics.com https://secure.gravatar.com https://www.facebook.com/tr/ https://ssl.gstatic.com/; font-src 'self' data: https://fonts.gstatic.com; connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com; media-src 'self'; object-src 'none'; frame-src 'self' td.doubleclick.net https://clarity.microsoft.com https://www.youtube.com https://videolevels.com https://app.sli.do https://business.facebook.com https://www.facebook.com/ https://www.google.com/recaptcha/; worker-src 'self'; base-uri 'self'; manifest-src 'self'; frame-ancestors 'self'
content-type: text/html; charset=UTF-8
date: Mon, 24 Aug 2026 08:36:35 GMT
expires: Mon, 24 Aug 2026 08:36:35 GMT
keep-alive: timeout=5, max=100
last-modified: Mon, 24 Aug 2026 08:36:36 GMT
server: Apache / ZoneOS
strict-transport-security: max-age=31536000
vary: Accept-Encoding
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 1; mode=block
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1604 ms._

**Scoring:** 11 errors · 10 warnings · 81 cosmetic (suppressed)

### Priority fixes
1. **No space between attributes.** (medium) — x3, first at line 358
2. **Attribute “stylr” not allowed on element “a” at this point.** (medium) — x1, first at line 356
3. **Duplicate ID “select-finansai-ir-draudimas”.** (medium) — x1, first at line 358
4. **Duplicate ID “select-draudimas”.** (medium) — x1, first at line 358
5. **Duplicate ID “select-kapitalo-rinkos”.** (medium) — x1, first at line 358

### Issue groups
- (×3) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 97 `33;" />
		<script type="text/javascript">
			(f`
- (×1) [error] Attribute “stylr” not allowed on element “a” at this point. — first at line 356 `<a href="https://www.sorainen.com/lt/newsletter/" class="btn btn-primary btn-pri`
- (×3) [error] No space between attributes. — first at line 358 `-text" value=""plac`
- (×1) [error] Duplicate ID “select-finansai-ir-draudimas”. — first at line 358 `a</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [warning] The first occurrence of ID “select-finansai-ir-draudimas” was here. — first at line 358 `s</option><option id="select-finansai-ir-draudimas" value="finansai-ir-draudimas`
- (×1) [error] Duplicate ID “select-draudimas”. — first at line 358 `s</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [warning] The first occurrence of ID “select-draudimas” was here. — first at line 358 `ė</option><option id="select-draudimas" value="draudimas" data-name=" - Draudima`
- (×1) [error] Duplicate ID “select-kapitalo-rinkos”. — first at line 358 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [warning] The first occurrence of ID “select-kapitalo-rinkos” was here. — first at line 358 `s</option><option id="select-kapitalo-rinkos" value="kapitalo-rinkos" data-name=`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas-ir-statyba”. — first at line 358 `i</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas-ir-statyba” was here. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas-ir-statyba" value="nekilnojam`
- (×1) [error] Duplicate ID “select-nekilnojamasis-turtas”. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [warning] The first occurrence of ID “select-nekilnojamasis-turtas” was here. — first at line 358 `a</option><option id="select-nekilnojamasis-turtas" value="nekilnojamasis-turtas`
- (×1) [error] Duplicate ID “select-statyba”. — first at line 358 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [warning] The first occurrence of ID “select-statyba” was here. — first at line 358 `s</option><option id="select-statyba" value="statyba" data-name=" - Statyba"> - `
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 458 `m>
</div>
</p>
    <`
- (×1) [warning] This document has heading elements but none of them has a computed heading level of 1. — first at line 267 `<h2 class="postsEmpty__title">Nėra r`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 3674 ms._

**Scoring:** 8 violations · 50 passes · critical 3 · serious 3 · moderate 2 · minor 0

### Priority fixes
1. **button-name** (high) — Buttons must have discernible text
2. **label** (high) — Form elements must have labels
3. **select-name** (high) — Select element must have an accessible name
4. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
5. **label-title-only** (high) — Form elements should have a visible label

### Findings

#### `button-name` (critical) — WCAG: wcag2a, wcag412
[Buttons must have discernible text](https://dequeuniversity.com/rules/axe/4.11/button-name?application=playwright)
- `.col-tp-none`
- `#alm-filter-1 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-5 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`
- `#alm-filter-6 > .alm-filter--inner > .alm-filter--text > .alm-filter--text-wrap.has-button > .alm-filters-button[type="button"]`

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `#menu-item-115923 > a`
- `#menu-item-5498 > a`
- `a[aria-current="page"]`
- `#menu-item-115926 > a`
- `#menu-item-5501 > a`
- … and 5 more nodes

#### `label-title-only` (serious)
[Form elements should have a visible label](https://dequeuniversity.com/rules/axe/4.11/label-title-only?application=playwright)
- `.search-field`

#### `label` (critical) — WCAG: wcag2a, wcag412
[Form elements must have labels](https://dequeuniversity.com/rules/axe/4.11/label?application=playwright)
- `#search-text-1`

#### `landmark-unique` (moderate)
[Landmarks should have a unique role or role/label/title (i.e. accessible name) combination](https://dequeuniversity.com/rules/axe/4.11/landmark-unique?application=playwright)
- `.siteHeader__nav`

#### `link-name` (serious) — WCAG: wcag2a, wcag244, wcag412
[Links must have discernible text](https://dequeuniversity.com/rules/axe/4.11/link-name?application=playwright)
- `.btn-close`
- `.fsocialLinks__item:nth-child(1) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(2) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(3) > a[rel="noopener noreferrer"][target="_blank"]`
- `.fsocialLinks__item:nth-child(4) > a[rel="noopener noreferrer"][target="_blank"]`

#### `region` (moderate)
[All page content should be contained by landmarks](https://dequeuniversity.com/rules/axe/4.11/region?application=playwright)
- `.skip-link`
- `.siteHeader__title.col-m-none`
- `.postsHeader`
- `.postsSide__title.h3`
- `.btn-primary--purple.btn-primary.btn:nth-child(2)`
- … and 18 more nodes

#### `select-name` (critical) — WCAG: wcag2a, wcag412
[Select element must have an accessible name](https://dequeuniversity.com/rules/axe/4.11/select-name?application=playwright)
- `#taxonomy-select-2`
- `#taxonomy-select-3`
- `#taxonomy-select-4`

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 1 node
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 18 nodes
- [<video> elements must have captions](https://dequeuniversity.com/rules/axe/4.11/video-caption?application=playwright) — 1 node

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 3690 ms._

**Capture summary:** 8 console events · 0 mixed-content requests · 64 network requests · 1.65 MB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| script | 26 | 1.08 MB |
| other | 1 | 312.4 KB |
| font | 4 | 119.8 KB |
| stylesheet | 9 | 77.7 KB |
| image | 10 | 48.8 KB |
| document | 3 | 19.3 KB |
| xhr | 2 | 3.1 KB |
| fetch | 8 | 798 B |
| ping | 1 | 0 B |

**Third-party origins (by bytes):**
- https://www.gstatic.com — 5 requests, 980.8 KB
- https://www.googletagmanager.com — 2 requests, 328.6 KB
- https://fonts.gstatic.com — 1 request, 39.2 KB
- https://www.clarity.ms — 1 request, 862 B
- https://cdn-cookieyes.com — 8 requests, 44 B
- https://hello.myfonts.net — 3 requests, 0 B
- https://www.google.com — 5 requests, 0 B
- https://log.cookieyes.com — 1 request, 0 B
- https://region1.google-analytics.com — 1 request, 0 B

**Slowest requests (top 5):**
- https://www.sorainen.com/lt/naujienos/ (document) — 518 ms, 19.3 KB
- https://www.sorainen.com/wp-admin/admin-ajax.php?action=alm_get_posts&query_type=standard&id=posts_list&post_id=0&slug=home&canonical_url=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&posts_per_page=5&page=0&offset=0&original_offset=0&post_type=post&repeater=default&seo_start_page=1&filters=true&filters_startpage=0&filters_target=posts_filter&facets=false&preloaded=true&preloaded_amount=5&lang=lt&order=DESC&orderby=date&currentPage=2 (xhr) — 500 ms, 3.1 KB
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/refill (fetch) — 375 ms, 2 B
- https://www.sorainen.com/lt/wp-json/contact-form-7/v1/contact-forms/11606/feedback/schema (fetch) — 374 ms, 752 B
- https://www.sorainen.com/lt/naujienos (document) — 345 ms, 0 B

### Priority fixes
1. **failed request** (medium) — fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560596477&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1180174349&_eu=AAAAAGAC&are=1&cid=612219591.1787560597&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315471~120385422&sid=1787560596&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1392 — net::ERR_ABORTED
2. **failed request** (medium) — fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
3. **failed request** (medium) — xhr: https://hello.myfonts.net/count/38fd6e — csp
4. **console error** (medium) — requestStorageAccess: Permission denied.
5. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
6. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
7. **console error** (medium) — Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.

### Findings

#### Failed requests
- fetch: https://region1.google-analytics.com/g/collect?v=2&tid=G-05KWKD0TXJ&gtm=45je68j0v898627717z8835828663za20gzb835828663zd835828663&_p=1787560596477&gcs=G100&gcd=13q3qPq2q5l1&npa=1&dma_cps=-&dma=1&ecid=1180174349&_eu=AAAAAGAC&are=1&cid=612219591.1787560597&ec_mode=a&frm=0&gtm_up=1&pscdl=denied&rcb=13&sr=1280x720&uaa=x86&uab=64&uafvl=Chromium%3B148.0.7778.96%7CHeadlessChrome%3B148.0.7778.96%7CNot%252FA)Brand%3B99.0.0.0&uam=&uamb=0&uap=Linux&uapv=&uaw=0&ul=en-us&gaf=2&_s=1&tag_exp=115616986~115938466~115938468~118897920~118897930~119367802~119367810~120213116~120315471~120385422&sid=1787560596&sct=1&seg=0&dl=https%3A%2F%2Fwww.sorainen.com%2Flt%2Fnaujienos%2F&dt=Naujienos%20-%20Sorainen&_tu=CA&en=page_view&_fv=1&_nsi=1&_ss=1&ep.debug_mode=true&tfd=1392 — net::ERR_ABORTED
- fetch: https://www.google.com/recaptcha/api2/clr?k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725 — net::ERR_ABORTED
- xhr: https://hello.myfonts.net/count/38fd6e — csp
- xhr: https://hello.myfonts.net/count/390cc4 — csp
- xhr: https://hello.myfonts.net/count/38fd79 — csp
- xhr: https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css — net::ERR_FAILED

#### Console events
- [error] requestStorageAccess: Permission denied. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=gfbxgblu4con)
- [error] Connecting to 'https://hello.myfonts.net/count/38fd6e' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/390cc4' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [error] Connecting to 'https://hello.myfonts.net/count/38fd79' violates the following Content Security Policy directive: "connect-src 'self' https://stats.g.doubleclick.net https://px.ads.linkedin.com *.analytics.google.com *.cookieyes.com cdn-cookieyes.com https://my.yoast.com https://d3hb14vkzrxvla.cloudfront.net *.google-analytics.com https://support.play.ee https://www.google.com https://s.clarity.ms https://www.facebook.com". The action has been blocked.
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Access to XMLHttpRequest at 'https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css' from origin 'https://www.google.com' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource. (https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&co=aHR0cHM6Ly93d3cuc29yYWluZW4uY29tOjQ0Mw..&hl=en&v=xg_pWYS8-HRESiV6Rdg4aY_R&size=invisible&anchor-ms=20000&execute-ms=30000&cb=gfbxgblu4con)
- [warning] Couldn't load preload assets:  ProgressEvent
- [error] Failed to load resource: net::ERR_FAILED (https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/styles__ltr.css)

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 3690 ms._

**Document:**
- Lang: lt-LT
- Title: Naujienos - Sorainen
- Canonical: https://www.sorainen.com/lt/naujienos/
- Viewport: width=device-width, initial-scale=1.0
- Charset: UTF-8
- HTML bytes: 134783

**Meta tags:**
- Description: not set
- Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
- Theme color: #1F1F5E
- Open Graph tags: 9 (og:locale, og:type, og:title, og:url, og:site_name, og:image, og:image:width, og:image:height, og:image:type)
- Twitter tags: 1
- hreflang:
  - en → https://www.sorainen.com/newsroom/
  - et → https://www.sorainen.com/et/uudised/
  - lv → https://www.sorainen.com/lv/zinas/
  - lt → https://www.sorainen.com/lt/naujienos/
  - x-default → https://www.sorainen.com/newsroom/
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×0, h2 ×1, h3 ×18, h4 ×1, h5 ×0, h6 ×0
- Sequence (first 20):
  - h2: Nėra rezultatų
  - h3: Privatiems klientams padedame apsaugoti, auginti ir perduoti turtą ateities kart
  - h3: Mokesčių naujienos: 2026 m. antrasis ketvirtis
  - h3: „Sorainen“ paskelbė 2026 m. tvarumo ataskaitą: atsakingas augimas per kryptingą 
  - h3: „Sorainen“ jau rekordinį dešimtą kartą pripažinta IFLR Baltijos metų teisės firm
  - h3: „Sorainen“ pripažinta Baltijos šalių metų teisės firma „Chambers Europe“ 2026 m.
  - h3: Stipriname ginčų ir ESG kompetencijas: prie komandos jungiasi advokatė Renata Ja
  - h3: 2026 metų Baltijos sandoriai: „Salling Group“, „Tele2“ / „Manulife“, „nexos.ai“,
  - h3: „Sorainen“ reikšmingai stiprina savo komandą: daugiausiai partnerių ir stipriaus
  - h3: „Sorainen“ paskyrė tris naujus partnerius
  - h3: Mūsų komanda pelnė pirmas pozicijas „Chambers FinTech 2026“ reitinguose visose B
  - h3: Užsisakykite mūsų naujienlaiškį!
  - h3: Ieškoti naujienų
  - h3: Raktiniai žodžiai
  - h3: Sektorius
  - h3: Paslauga
  - h3: Šalis
  - h3: Data
  - h3: Data
  - h4: Domina aktualios verslo teisės naujienos?

**Landmarks:**
- nav: present
- main: **missing**
- header: present
- footer: present
- Skip-to-content link: **missing**

**Scripts:** 47 total — 1 defer, 6 async, 17 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://www.googletagmanager.com/gtag/js?id=G-05KWKD0TXJ&cx=c&gtm=4e68j0 (async)
- https://www.gstatic.com/recaptcha/releases/xg_pWYS8-HRESiV6Rdg4aY_R/recaptcha__en.js (async)
- https://www.googletagmanager.com/gtm.js?id=GTM-TP84RL9 (async)
- https://www.clarity.ms/tag/mcx1zjswj9?ref=wordpress (async)
- https://www.sorainen.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=497000 (defer)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5
- https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js
- https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/banner.js (async)
- https://www.sorainen.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-contact-form-7-tracker.js?ver=1.22.5
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/vendors.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/main.min.js?ver=1786527802
- https://www.sorainen.com/wp-content/themes/sorainen/build/js/ajax.min.js?ver=7.0.4
- https://www.google.com/recaptcha/api.js?render=6LfPx40qAAAAAI1aJSj1kM7_jE73_mrwDkkDU725&ver=3.0
- https://www.sorainen.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0

**Stylesheets:** 5 external, 5 inline (27.0 KB)

**Images:** 4 total — **0 without alt**, **4 without width/height**, 4 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| https://cdn-cookieyes.com/assets/images/close.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| https://cdn-cookieyes.com/assets/images/poweredbtcky.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| -content/themes/sorainen/build/img/logo__sorainen--light.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |
| .com/wp-content/themes/sorainen/build/img/logo__sorainen.svg | _(empty)_ | _n/a_ | _n/a_ | ✗ |

**Links:** 88 anchors — 7 external, 0 preconnect, 0 preload.

Vague repeated link text:
- "eva berlaus" ×5
- "naujienos" ×3
- "saulė dagilytė" ×3
- "dr mindaugas lukas" ×3
- "sorainen" ×2
- "paslaugos" ×2
- "komanda" ×2
- "karjera" ×2
- "apie mus" ×2
- "kontaktai" ×2

**Forms:**
Form 1:
- search — **no label**
Form 2:
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- text — **no label**
- email — **no label**
- text — **no label**
- text — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- checkbox — **no label**
- select — **no label**
- checkbox — **no label**
- submit — **no label**

### Priority fixes
1. **Document has 0 <h1> elements** (high) — A page should have exactly one h1; multiple h1s break document outline
2. **Missing skip-to-content link** (medium) — No anchor link with "skip" / "otse sisu" text found
3. **4 images without explicit width/height** (medium) — Missing dimensions can cause layout shifts (CLS)
4. **17 render-blocking external scripts** (medium) — Only 1 defer, 6 async; add defer/async to non-critical scripts

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 1 pass · 0 warn · 1 fail · 5 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) |
| Images lazy-loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero image eagerly loaded | – n/a | No raster <img> elements found (4 SVGs excluded). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 0 raster images on the page (4 SVGs excluded) — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✗ fail | 3 render-blocking scripts in <head>. Move to footer or add defer/async. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WPML ver:4.9.7 stt:1,15,32,33;`
- JS scripts not blocking in <head>:
  - `…tomi-google-tag-manager/dist/js/analytics-talk-content-tracking.js?ver=1.22.5`
  - `https://www.sorainen.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1`
  - `https://cdn-cookieyes.com/client_data/627e335d11f737396c21224f/script.js`

### Priority fixes
1. **JS scripts not blocking in <head>** (high) — 3 render-blocking scripts in <head>. Move to footer or add defer/async.

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).