20260703T061513Z-77b4
- Audited URL
- https://thediplomat.ee/
- Timestamp
- 2026-07-03T06:20:09.785Z
- Kind
- site
- Pages
- 5
Weighted audit summary
Site overall 78 is the mean of 5 pages. Scores range 74 (https://thediplomat.ee/faq) → 82 (https://thediplomat.ee/). Weakest page: Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.
# Audit Report: A place with a character. In a neighbourhood that has one too. - The Diplomat
Website: https://thediplomat.ee/
Date: 2026-07-03
Overall Score: 78 / 100
Status: 🟡 Needs Improvement
Confidence: high
Audit Coverage: 100% — all sources returned data
Pages Audited (5 of 5):
- https://thediplomat.ee/
- https://thediplomat.ee/contact
- https://thediplomat.ee/faq
- https://thediplomat.ee/et/kkk
- https://thediplomat.ee/for-business-customers
Summary
Site overall 78 is the mean of 5 pages. Scores range 74 (https://thediplomat.ee/faq) → 82 (https://thediplomat.ee/). Weakest page: Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.
Per-Page Scores
| Page | Score | Status | Confidence |
|---|---|---|---|
| https://thediplomat.ee/ | 82 | 🟡 Needs Improvement | high |
| https://thediplomat.ee/contact | 78 | 🟡 Needs Improvement | high |
| https://thediplomat.ee/faq | 74 | 🟡 Needs Improvement | high |
| https://thediplomat.ee/et/kkk | 76 | 🟡 Needs Improvement | high |
| https://thediplomat.ee/for-business-customers | 78 | 🟡 Needs Improvement | high |
PageSpeed Insights — Mobile vs Desktop
Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.
| URL | Performance (M / D) | LCP (M / D) | CLS (M / D) |
|---|---|---|---|
| https://thediplomat.ee/ | 91 / 100 | 3.16 s / 776 ms | 0.012 / 0.000 |
| https://thediplomat.ee/contact | 94 / 99 | 2.75 s / 910 ms | 0.010 / 0.000 |
| https://thediplomat.ee/faq | 88 / 100 | 2.96 s / 731 ms | 0.000 / 0.000 |
| https://thediplomat.ee/et/kkk | 88 / 99 | 3.05 s / 724 ms | 0.000 / 0.001 |
| https://thediplomat.ee/for-business-customers | 94 / 99 | 2.87 s / 873 ms | 0.016 / 0.001 |
Optimization Checklist
4 of 4 passing — 4 pass · 0 warn · 0 fail · 3 n/a
| Item | Status | Detail |
|---|---|---|
| Page caching plugin / CDN active | Pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | Pass | All non-hero raster images use loading="lazy" except one. |
| Hero image eagerly loaded | Pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | N/A | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | N/A | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | N/A | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | Pass | No render-blocking scripts in <head>. |
Fixes
Priority 1: Critical
Immediate action — impacts user experience, search rankings, or site safety.
1A. Add HSTS and Content-Security-Policy headers
- Impact: Security Headers Grade, XSS/Clickjacking protection
- Problem: Security Headers grade is 13/100; HSTS and CSP are missing despite site signals indicating user-generated content (upload link).
- Solution:
Add HSTS with preload and a strict CSP:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';
1B. Fix serious color-contrast violation
- Impact: WCAG 1.4.3 Compliance, Accessibility Score
- Problem: axe-core reports 1 serious violation on
.button--secondarywhere background and foreground colors lack sufficient contrast. - Solution: Increase contrast ratio to at least 4.5:1 for the secondary button text. Use a darker text color or lighter background in CSS.
1C. Enforce HTTPS redirect and add HSTS
Impact: Transport security, data integrity
Problem: HTTP does not redirect to HTTPS (http://thediplomat.ee/contact stays on HTTP), and HSTS is missing. Security Headers grade is 13/100.
Solution: Configure the web server or CDN (Cloudflare) to redirect all HTTP traffic to HTTPS immediately.
Cloudflare Page Rule:
- URL:
thediplomat.ee/* - Setting:
Always Use HTTPS
Apache/Nginx (Origin):
RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]Add HSTS Header:
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"- URL:
1D. Implement Content Security Policy (CSP)
Impact: XSS protection, data exfiltration prevention
Problem: CSP is missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS risk high per the security rubric.
Solution: Deploy a strict CSP with nonces for scripts. Start with a report-only mode to avoid breaking WP Rocket/CDN scripts.
Header:
Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic' https:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'self';"Implementation:
- Generate a random nonce per request in PHP/WordPress.
- Add
nonce="{NONCE}"to all<script>tags. - Monitor
Content-Security-Policy-Report-Onlybefore enforcing.
1E. Enforce HTTPS and Add Critical Security Headers
- Impact: Transport security, XSS protection, clickjacking
- Problem: HTTP does not redirect to HTTPS, and HSTS/CSP are missing. Site signals indicate User-Generated Content (textarea/upload), making XSS protection critical.
- Solution:
Configure server/CDN to redirect all HTTP traffic to HTTPS. Add the following headers:
Strict-Transport-Security: max-age=63072000; includeSubDomains; preload Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; X-Frame-Options: SAMEORIGIN
1F. Fix Critical ARIA Attribute Values
- Impact: Accessibility (WCAG 4.1.2)
- Problem: Critical axe violation:
aria-expandeduses value '1' instead of 'true'/'false' on accordion buttons. W3C validator confirms 4 instances of this error. - Solution:
Update accordion buttons to use boolean strings:
<button aria-expanded="true" aria-controls="..."> Toggle Section </button>
1G. Force HTTPS redirect and add HSTS
- Impact: Transport security, MITM protection
- Problem: HTTP does not redirect to HTTPS (http://thediplomat.ee/et/kkk does not redirect) and HSTS is missing, leaving users vulnerable on insecure connections.
- Solution:
Configure the web server (Nginx/Apache) to return 301 redirects for all HTTP traffic to HTTPS. Add HSTS header:
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
Priority 2: Important
Essential for compliance, user reach, and search visibility.
2A. Optimize Largest Contentful Paint (LCP)
- Impact: Performance Score, LCP Metric
- Problem: Mobile LCP is 3.2 s (warning zone), flagged by PSI
largest-contentful-paintandimage-delivery-insight. - Solution:
- Preload the LCP image resource.
- Ensure hero image uses
fetchpriority="high". - Convert remaining heavy images to WebP/AVIF if not already done.
2B. Fix W3C script type/defer errors
- Impact: HTML Validity, Potential JS Execution Issues
- Problem: W3C Validator reports 4 errors where
scriptelements with non-standardtypeattributes (e.g.,text/rocketlazyloadscript) incorrectly use thedeferattribute. - Solution:
Update WP Rocket configuration or custom scripts to remove
deferfrom non-standard script types, or changetypetotext/javascriptwhere appropriate.
2C. Fix W3C Validation Errors (Scripts & ARIA)
Impact: Maintainability, Accessibility compliance
Problem: 19 W3C errors found, including 11 instances of
type="text/rocketlazyloadscript"withdeferand 3 invalidaria-expanded=""attributes.Solution:
- Scripts: Remove
typeattribute from standard JS or use valid MIME types (text/javascript). WP Rocket's lazyload script type is non-standard. - ARIA: Fix
aria-expandedto betrueorfalse(not empty string). - Hidden Inputs: Remove
autocompletefromtype="hidden"inputs.
Example Fix:
<!-- Before --> <button aria-expanded="" ...> <!-- After --> <button aria-expanded="false" ...>- Scripts: Remove
2D. Add Meta Description and Structured Data
Impact: SEO, Search Result CTR
Problem: PSI SEO audit fails
metaDescriptionandstructuredData. HTML Inventory confirms Description is not set.Solution: Add a unique meta description (150-160 chars) in the
<head>.<meta name="description" content="Contact The Diplomat for inquiries regarding apartments, payments, and general support. Reach out via our secure form.">Add JSON-LD for
ContactPageorLocalBusiness:<script type="application/ld+json"> { "@context": "https://schema.org", "@type": "ContactPage", "name": "Contact The Diplomat" } </script>
2E. Add Meta Description for SEO
- Impact: SEO (Search Snippets)
- Problem: W3C and PSI report missing meta description. This affects click-through rates in search results.
- Solution:
Add a concise description (150–160 characters) in the
<head>:<meta name="description" content="Frequently asked questions about The Diplomat apartments, payments, and move-in process.">
2F. Fix W3C validation errors and ARIA attributes
- Impact: Accessibility, Standards compliance
- Problem: 19 W3C errors including invalid
aria-expanded="1"(should be true/false) and invalid script types withdeferattribute. - Solution:
- Update
aria-expandedvalues to boolean strings (true/false). - Remove
type="text/rocketlazyloadscript"or use valid MIME types for scripts. - Fix hidden input autocomplete attributes per W3C spec.
- Update
2G. Add Meta Description
- Impact: SEO, Click-through rate
- Problem: SEO audit flags
metaDescriptionas missing; document has no description tag. - Solution:
Add a concise description (150–160 chars) in the
<head>:<meta name="description" content="Korduma kippuvad küsimused The Diplomat'i teenuste kohta. Leia vastused broneerimise, maksete ja majutuse küsimustele.">
2H. Fix W3C HTML Validation Errors
- Impact: Maintainability, Compliance
- Problem: 15 errors found, including 11 instances of
scriptwith invalidtypeattributes (WP Rocket) and hidden inputs withautocomplete. - Solution:
- Remove
typeattribute from standard JS scripts (or use valid MIME types). - Remove
autocompletefrominput type="hidden"elements. - Move
meta charsetto the first 1024 bytes of the document. - Fix unclosed
<p>tags.
- Remove
Priority 3: Best Practice
Recommended for long-term maintainability.
3A. Ensure lazy loading for below-fold images
- Impact: Page Weight, Initial Load Time
- Problem: HTML Inventory shows 2 images missing
loading="lazy"despite being below the fold. - Solution:
Add
loading="lazy"to all<img>tags that are not the LCP element or above the fold.
3B. Optimize LCP and Font Loading
Impact: Core Web Vitals (LCP 2.8 s)
Problem: Mobile LCP is 2.8 s (warning zone). PSI suggests 80 ms savings from font-display and 142 KiB from image delivery.
Solution:
- Fonts: Add
font-display: swapto CSS or usedisplay=swapin Google Fonts URL. - Images: Ensure the LCP image (likely the hero) is preloaded or has
fetchpriority="high"(already present per checklist, verify priority). - Images: Convert remaining raster images to WebP/AVIF if not already done.
Google Fonts:
<link href="https://fonts.googleapis.com/css?family=Open+Sans&display=swap" rel="stylesheet">- Fonts: Add
3C. Resolve W3C HTML Validation Errors
- Impact: Maintainability, Browser Compatibility
- Problem: 19 errors found, including invalid script types (
text/rocketlazyloadscriptwithdefer) and hidden inputs withautocomplete. - Solution:
- Remove
deferfrom non-JavaScript script types (WP Rocket optimization). - Remove
autocompletefromtype="hidden"inputs. - Move
meta charsetto the first 1024 bytes of the document.
- Remove
3D. Optimize LCP and Image Delivery
- Impact: Performance (LCP 2.9 s)
- Problem: LCP is 2.9 s (warning threshold) and PSI suggests 187 KiB savings via image delivery optimization.
- Solution:
- Convert remaining JPEGs to WebP/AVIF.
- Ensure the LCP image (likely the hero) has
fetchpriority="high". - Preload the LCP image resource in the
<head>.
▸Raw Markdown sent to the LLM
# Site Audit — https://thediplomat.ee/
Run: 2026-07-03T06:15:14.168Z
Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**
Pages audited:
- https://thediplomat.ee/
- https://thediplomat.ee/contact
- https://thediplomat.ee/faq
- https://thediplomat.ee/et/kkk
- https://thediplomat.ee/for-business-customers
---
# Page 1 of 5 — https://thediplomat.ee/
Run: 2026-07-03T06:15:15.396Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 19342 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **91** | 100 |
| Accessibility | **90** | 96 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.2 s** | 0.8 s |
| CLS | **0.012** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **2.10 s** | 500 ms |
| Speed Index | **2.10 s** | 500 ms |
| TTFB | **6 ms** | 4 ms |
### Priority fixes
1. **largest-contentful-paint** (medium) — 3.2 s
2. **first-contentful-paint** (low) — 2.1 s
3. **font-display-insight** (high) — Est savings of 30 ms
4. **image-delivery-insight** (high) — Est savings of 86 KiB
5. **network-dependency-tree-insight** (high)
### Findings (mobile)
#### Layout-shift sources
- main#main > div.section > div.hero__title-wrapper > div.h-container — shift 0.012
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.73, weight 25) — Largest Contentful Paint — 3.2 s
- `first-contentful-paint` (performance, score 0.81, weight 10) — First Contentful Paint — 2.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 112 ms._
**Transport:**
- Final URL: https://thediplomat.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓
**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: Fri, 03 Jul 2026 06:14:22 GMT
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 125.0 KB
### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
5. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
6. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
7. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
8. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
9. **server header discloses technology** (low) — Server: cloudflare
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None
#### Info disclosure
- Server: `cloudflare`
#### All response headers
```
age: 53
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cf-cache-status: HIT
cf-ray: a153c1313b15c7e7-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:15 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,d6f37d52171526195ac378710986608eaa33383690ec9b71b230c6afdfd5199d
ki-cache-type: Edge
ki-cf-cache-status: HIT
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
last-modified: Fri, 03 Jul 2026 06:14:22 GMT
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/2>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SuBO1CAavTTwNWUBH%2FrIUtt2rA7JCG6G2WRFoVeh%2FBYTbrCiFtP%2FFFC4MEv4awMvkYG1Uqyt8d9s3PorsXxDxMCi7bibilIaPf8DnLVkYDzTlyvQfvIv6v4G6uivR7hr"}]}
server: cloudflare
set-cookie: __cf_bm=68DmxnkTJoa7.XOuaWFt0ux9IX_v0jF..P3zlvIvYH8-1783059315.3994324-1.0.1.1-sFZvsG7LjmwxPR_jH2Pdst9Z7xJd89lbGHg8qSEemQb5QXEavfd2Of.LIRY22RWLJE3yAZYQHKq6S6tErqHl8fggTpsbp2TRuYnGJpr1ygMb9J5_.E2HYkckU.7nNqCW; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:15 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 725 ms._
**Scoring:** 4 errors · 9 warnings · 40 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x4, first at line 1628
### Issue groups
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 468 `/noscript><script nowprocket type="text/javascript">var el`
- (×6) [warning] Article lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all articles. — first at line 523 `<article class="room-card room-card--display carousel__card">
<`
- (×1) [warning] Empty heading. — first at line 814 `<h2 class="cta__title h2"></h2>`
- (×4) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 1628 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1735 ms._
**Scoring:** 2 violations · 41 passes · critical 0 · serious 1 · moderate 0 · minor 1
### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **empty-heading** (low) — Headings should not be empty
### Findings
#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.button--secondary > .button__inner > .button__text`
#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `.cta__title`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 10 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1748 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 23 network requests · 546.2 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 7 | 471.6 KB |
| font | 2 | 45.9 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 1 | 0 B |
| other | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 142 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 130 ms, 0 B
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 73 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/pathway-extreme-regular.woff2 (font) — 73 ms, 29.6 KB
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/antonio-bold.woff2 (font) — 73 ms, 16.3 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1748 ms._
**Document:**
- Lang: en
- Title: A place with a character.
In a neighbourhood that has one too. - The Diplomat
- Canonical: https://thediplomat.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 122543
**Meta tags:**
- Description: This is an example page. It's different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 8
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown
**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×3, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: A place with a character.
In a neighbourhood that has one too.
- h2: At the intersection of calm and central
- h2: You may also like
- h2:
- h2: Why stay with us?
- h2: In the neighbourhood
- h3: The Old Town
- h3: Bay of Tallinn
- h3: Downdown & Rotermann
- h2: Small country, short distances.
- h2: The Diplomat way
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 22 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.4 KB)
**Images:** 25 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/e8d4ce07c088fedd0c5f9440ed88c14722cda6ad-320x180.jpg | _(empty)_ | 320×180 | eager | ✓ |
| ://thediplomat.ee/wp-content/uploads/2026/06/501-280x155.jpg | 501.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_2-280x155.jpg | 208_2.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_1-280x155.jpg | 208_1.jpg | 280×155 | lazy | ✓ |
| ://thediplomat.ee/wp-content/uploads/2026/06/505-280x155.jpg | 505.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_1-280x155.jpg | 208_1.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/510_5-280x155.jpg | 510_5.jpg | 280×155 | lazy | ✓ |
| /2026/06/bd904a05d03dd97f3298ab818a9187d1748380cd-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| ediplomat.ee/wp-content/uploads/2026/07/0d3a0784-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/82d207c5f9b11f700807b888b95c3424c15f4d4a-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/85ae5996681b2812414ab3e94020d5e3bbff7ec8-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/297cf245a09f8d821a107c0f6cd2372ebae83b8a-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| hediplomat.ee/wp-content/uploads/2026/07/ext-4-1-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/34f8e37c0ee3206f9427630e733913d8fbb46ab0-100x100.png | _(empty)_ | 100×100 | lazy | ✓ |
| 2026/06/382f74d29e319e4424ba7bd3e2d3d00f507e22dc-320x180.png | _(empty)_ | 320×180 | lazy | ✓ |
**Links:** 34 anchors — 11 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "get location" ×3
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2
- "+372 5666 9544" ×2
**Forms:**
Form 1:
- text — labeled
- text — labeled
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy" except one. |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 25/25 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 30 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.22.0.3`
- `CDN: Cloudflare, Kinsta (HIT)`
- Images lazy-loaded:
- `…p-content/uploads/2026/06/bd904a05d03dd97f3298ab818a9187d1748380cd-120x35.jpg`
- Hero image eagerly loaded:
- `hero: …-content/uploads/2026/06/e8d4ce07c088fedd0c5f9440ed88c14722cda6ad-320x180.jpg`
- `loading: eager`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 100, 120, 150, 200, 207, 280, 300, 320, 400, 413, 480, 560, 640, 768, 800, 840, 960, 1024, 1120, 1400, 1440, 1536, 1600, 1680, 1920, 1960, 2048, 2240, 2560, 3200`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 2 of 5 — https://thediplomat.ee/contact
Run: 2026-07-03T06:15:15.398Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 11551 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 99 |
| Accessibility | **94** | 100 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.8 s** | 0.9 s |
| CLS | **0.010** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **1.99 s** | 720 ms |
| Speed Index | **1.99 s** | 720 ms |
| TTFB | 3 ms | **4 ms** |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (low) — 2.0 s
3. **document-latency-insight** (high) — Est savings of 470 ms
4. **font-display-insight** (high) — Est savings of 80 ms
5. **image-delivery-insight** (high) — Est savings of 142 KiB
### Findings (mobile)
#### Layout-shift sources
- div.grid > div.grid__col > div.location__box > ul.location__list — shift 0.010
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.84, weight 25) — Largest Contentful Paint — 2.8 s
- `first-contentful-paint` (performance, score 0.84, weight 10) — First Contentful Paint — 2.0 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 588 ms._
**Transport:**
- Final URL: https://thediplomat.ee/contact/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/contact does not redirect to HTTPS (target: http://thediplomat.ee/contact/)
**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 101.7 KB
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/contact does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None
#### Info disclosure
- Server: `cloudflare`
#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b0c02bd94a32c32031ad1c6aee304445b4e80c3158186a82509219803000316c
cf-cache-status: DYNAMIC
cf-ray: a153c132bc4cc7e7-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:15 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b0c02bd94a32c32031ad1c6aee304445b4e80c3158186a82509219803000316c
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/43>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=43>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SPhsCfkvzhicY8%2BvlwJRravAGKf7Ip%2FKXXaNREPAU8HVjLqs5zpfJmdGUdP1ECwddiljkcKvPv0mMS%2BpTu3Ag%2Fz3HDYT5ROaafNmGWGhesSp%2BxkOfhhInMtyJFLBQEMl"}]}
server: cloudflare
set-cookie: __cf_bm=R0jBlC1_wM3UcWagTHY783ryqLSXJdCnQUipXWdumVE-1783059315.6393037-1.0.1.1-YRdd9gFkbx6QEjsjXZlt_Ob4wLkjo4uNHf__bUqVB99Mwmdjt2pgubr2JsRAbpwJQ3EYOQnWFN1I_LzQLhHgxTsidg1Q7e07BxI5_.BjQ2fWapgm_bImDJTZN7kLRFnu; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:15 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 779 ms._
**Scoring:** 19 errors · 5 warnings · 47 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 941
2. **Bad value “” for attribute “aria-expanded” on element “button”.** (medium) — x3, first at line 531
3. **No “p” element in scope but a “p” end tag seen.** (medium) — x2, first at line 462
4. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 764
5. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×2) [error] No “p” element in scope but a “p” end tag seen. — first at line 462 `llinn</p>
</p>`
- (×3) [error] Bad value “” for attribute “aria-expanded” on element “button”. — first at line 531 `<button
aria-controls="accordion-how-do-monthly-payments-and`
- (×3) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 544 `<section
aria-labelledby="accordion-how-do-monthly-payments-`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 764 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 817 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 941 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 2127 ms._
**Scoring:** 0 violations · 42 passes · critical 0 · serious 0 · moderate 0 · minor 0
### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 3 nodes
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 2136 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 19 network requests · 421.1 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 316.8 KB |
| font | 3 | 75.7 KB |
| script | 3 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://thediplomat.ee/contact (document) — 636 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 129 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 121 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/pathway-extreme-semibold.woff2 (font) — 66 ms, 29.8 KB
- https://thediplomat.ee/wp-content/uploads/2026/07/0v2a6253-1-960x720.jpg (image) — 64 ms, 79.8 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 2136 ms._
**Document:**
- Lang: en
- Title: Contact - The Diplomat
- Canonical: https://thediplomat.ee/contact/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 101311
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×3, h3 ×2, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Contact
- h2: Seamlessly connected
- h2: Got a question?
- h2: Leave a message
- h3: General
- h3: Lobby
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 36 total — 3 defer, 0 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
**Stylesheets:** 5 external, 3 inline (9.4 KB)
**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| thediplomat.ee/wp-content/uploads/2026/07/ext-4-1-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| iplomat.ee/wp-content/uploads/2026/07/0v2a6253-1-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |
**Links:** 22 anchors — 5 external, 1 preconnect, 2 preload.
Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2
**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.22.0.3`
- `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
- `hero: https://thediplomat.ee/wp-content/uploads/2026/07/ext-4-1-120x35.jpg`
- `loading: eager`
- `fetchpriority: high`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 3 of 5 — https://thediplomat.ee/faq
Run: 2026-07-03T06:15:38.242Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 14617 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **88** | 100 |
| Accessibility | **89** | 94 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.0 s** | 0.7 s |
| CLS | 0.000 | **0.000** |
| TBT | 0 ms | 0 ms |
| FCP | **2.73 s** | 539 ms |
| Speed Index | **4.36 s** | 539 ms |
| TTFB | **6 ms** | 3 ms |
### Priority fixes
1. **largest-contentful-paint** (low) — 3.0 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **speed-index** (low) — 4.4 s
4. **document-latency-insight** (high) — Est savings of 80 ms
5. **font-display-insight** (high) — Est savings of 40 ms
### Findings (mobile)
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `aria-valid-attr-value` (accessibility, score 0.00, weight 10) — `[aria-*]` attributes do not have valid values
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.79, weight 25) — Largest Contentful Paint — 3.0 s
- `first-contentful-paint` (performance, score 0.59, weight 10) — First Contentful Paint — 2.7 s
- `speed-index` (performance, score 0.75, weight 10) — Speed Index — 4.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 587 ms._
**Transport:**
- Final URL: https://thediplomat.ee/faq/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/faq does not redirect to HTTPS (target: http://thediplomat.ee/faq/)
**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 97.9 KB
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/faq does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None
#### Info disclosure
- Server: `cloudflare`
#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,eabc8c995bffa84a9e3c6a8a383a0b61c78ad1b5d97935c8b1aedb7ebf51e64f
cf-cache-status: DYNAMIC
cf-ray: a153c1c17f20543a-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:38 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,eabc8c995bffa84a9e3c6a8a383a0b61c78ad1b5d97935c8b1aedb7ebf51e64f
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/48>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=48>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=UYqQMsC7KcoMADt8nNfRzSQ2QVHh7pd0eRQJ9qA62L62N9dsKe1g4tYUwkShVNPy4AqpCEUFOSg%2FWsRXm7ej7aHXbfFDFynUG%2BlKMqnLMSgAtO0jxBVEoCmOZAnGj0g8"}]}
server: cloudflare
set-cookie: __cf_bm=7CGcsCkr0t7HRiXiP6bimerMAR1hJQZetbHfDmT_GIQ-1783059338.4769058-1.0.1.1-rr4zUOLXHqj73QaY54dQXByggZ6oj2553IQ169CX9LkGvb44aoGBv2OK5v0xGabXpyDWMyJ0kWDm4ka39EfPQUtM5UuH8NhVnLtJB47CLjDLiXJ.lZhVZJwTALhEsk6g; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:38 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 664 ms._
**Scoring:** 19 errors · 5 warnings · 45 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 863
2. **Bad value “1” for attribute “aria-expanded” on element “button”.** (medium) — x4, first at line 464
3. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 714
4. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 588
### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×4) [error] Bad value “1” for attribute “aria-expanded” on element “button”. — first at line 464 `<button
aria-controls="accordion-how-do-monthly-payments-and`
- (×4) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 477 `<section
aria-labelledby="accordion-how-do-monthly-payments-`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 588 `ther.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 714 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 790 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 863 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1976 ms._
**Scoring:** 1 violations · 42 passes · critical 1 · serious 0 · moderate 0 · minor 0
### Priority fixes
1. **aria-valid-attr-value** (high) — ARIA attributes must conform to valid values
### Findings
#### `aria-valid-attr-value` (critical) — WCAG: wcag2a, wcag412
[ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright)
- `#accordion-how-do-monthly-payments-and-fees-work-header`
- `#accordion-can-i-get-a-tour-of-the-room-header`
- `#accordion-how-does-move-in-process-work-header`
- `#accordion-can-i-sign-an-agreement-for-any-period-i-wish-header`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1983 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 19 network requests · 264.2 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 159.9 KB |
| font | 3 | 75.7 KB |
| script | 3 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://thediplomat.ee/faq (document) — 561 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 135 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 124 ms, 0 B
- https://thediplomat.ee/wp-content/uploads/2026/06/448c466d69b387f3b2c785f81292ebb76b046a791-960x720.jpg (image) — 66 ms, 81.1 KB
- https://thediplomat.ee/wp-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-1440x420.jpg (image) — 62 ms, 78.8 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1983 ms._
**Document:**
- Lang: en
- Title: FAQ - The Diplomat
- Canonical: https://thediplomat.ee/faq/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 97643
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Frequently asked questions
- h2: Didn’t find an answer?
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 36 total — 3 defer, 0 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
**Stylesheets:** 5 external, 3 inline (9.4 KB)
**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| 026/06/448c466d69b387f3b2c785f81292ebb76b046a791-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |
**Links:** 20 anchors — 4 external, 1 preconnect, 2 preload.
Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2
**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.22.0.3`
- `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
- `hero: …-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg`
- `loading: eager`
- `fetchpriority: high`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 4 of 5 — https://thediplomat.ee/et/kkk
Run: 2026-07-03T06:15:46.323Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 12345 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **88** | 99 |
| Accessibility | **89** | 94 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.1 s** | 0.7 s |
| CLS | 0.000 | **0.001** |
| TBT | 0 ms | 0 ms |
| FCP | **2.90 s** | 724 ms |
| Speed Index | **3.27 s** | 724 ms |
| TTFB | 4 ms | **20 ms** |
### Priority fixes
1. **largest-contentful-paint** (low) — 3.1 s
2. **first-contentful-paint** (medium) — 2.9 s
3. **document-latency-insight** (high) — Est savings of 240 ms
4. **font-display-insight** (high) — Est savings of 40 ms
5. **image-delivery-insight** (medium) — Est savings of 65 KiB
### Findings (mobile)
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `aria-valid-attr-value` (accessibility, score 0.00, weight 10) — `[aria-*]` attributes do not have valid values
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.76, weight 25) — Largest Contentful Paint — 3.1 s
- `first-contentful-paint` (performance, score 0.53, weight 10) — First Contentful Paint — 2.9 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 658 ms._
**Transport:**
- Final URL: https://thediplomat.ee/et/kkk/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/et/kkk does not redirect to HTTPS (target: http://thediplomat.ee/et/kkk/)
**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 97.2 KB
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/et/kkk does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None
#### Info disclosure
- Server: `cloudflare`
#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b27fe97603901a9385b4cab5adafb1e0271ed6d6d2ff9c557a7f569ae7997240
cf-cache-status: DYNAMIC
cf-ray: a153c1f46d907123-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:46 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b27fe97603901a9385b4cab5adafb1e0271ed6d6d2ff9c557a7f569ae7997240
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/et/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/et/wp-json/wp/v2/pages/134>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/et/?p=134>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=XSb%2FfKEWO1PRsy3umBT7%2BvR6SRd60AI3H6sGzJiHIIAYopQxDP6FepuWDmOHrHmZILukLAcEr8BB0EU%2BUfVUQUTuBMP%2FiHhhV%2FS1dbfnoC8tdebcZH%2BFmXSCKDMhc%2BfH"}]}
server: cloudflare
set-cookie: __cf_bm=nGMu9tgmjZowiv30VHceFyvrsz0tqA5tW4BM4wF5FbE-1783059346.622395-1.0.1.1-zIV93069w31rUMkdI_aF.8oLcfycQXl2_ngNiFS4rZoj9cfC5A_x4YdtI95HYxRkrvkd4ehmaUXAoQHE2U_54AZt1Oi0dE_frKZ59AVP.3A8oNqBJvu28ynu01l_8_dN; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:46 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 1023 ms._
**Scoring:** 19 errors · 5 warnings · 45 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 847
2. **Bad value “1” for attribute “aria-expanded” on element “button”.** (medium) — x4, first at line 464
3. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 714
4. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 588
### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×4) [error] Bad value “1” for attribute “aria-expanded” on element “button”. — first at line 464 `<button
aria-controls="accordion-kuidas-igakuised-maksed-ja-`
- (×4) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 477 `<section
aria-labelledby="accordion-kuidas-igakuised-maksed-`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 588 `duse.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 714 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 790 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 847 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1932 ms._
**Scoring:** 1 violations · 42 passes · critical 1 · serious 0 · moderate 0 · minor 0
### Priority fixes
1. **aria-valid-attr-value** (high) — ARIA attributes must conform to valid values
### Findings
#### `aria-valid-attr-value` (critical) — WCAG: wcag2a, wcag412
[ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright)
- `#accordion-kuidas-igakuised-maksed-ja-tasud-toimivad-header`
- `#accordion-kas-ma-saan-ruumi-naha-enne-broneerimist-header`
- `#accordion-kuidas-sissekolimine-toimub-header`
- `#accordion-kas-saan-solmida-lepingu-endale-sobivaks-perioodiks-header`
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1939 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 20 network requests · 264.2 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 159.9 KB |
| font | 3 | 75.7 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://thediplomat.ee/et/kkk (document) — 563 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 127 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 121 ms, 0 B
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 46 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (script) — 30 ms, 0 B
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1938 ms._
**Document:**
- Lang: et
- Title: KKK - The Diplomat
- Canonical: https://thediplomat.ee/et/kkk/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 96887
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: Korduma kippuvad küsimused
- h2: Ei saanud vastust oma küsimusele?
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 39 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.4 KB)
**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| 026/06/448c466d69b387f3b2c785f81292ebb76b046a791-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |
**Links:** 18 anchors — 2 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "korterid" ×2
- "naabruses" ×2
- "kkk" ×2
- "kontakt" ×2
**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.22.0.3`
- `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
- `hero: …-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg`
- `loading: eager`
- `fetchpriority: (not set)`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).
---
# Page 5 of 5 — https://thediplomat.ee/for-business-customers
Run: 2026-07-03T06:16:05.077Z
## Audit Coverage
**100%** of audit sources returned data.
_All sources OK._
## Methodology
Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.
Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.
Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.
## Site Signals (inferred)
Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.
- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no
## PageSpeed Insights
_Captured in 11925 ms (mobile + desktop in parallel)._
**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 99 |
| Accessibility | **94** | 100 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |
**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.9 s** | 0.9 s |
| CLS | **0.016** | 0.001 |
| TBT | 0 ms | 0 ms |
| FCP | **1.96 s** | 551 ms |
| Speed Index | **1.96 s** | 551 ms |
| TTFB | 3 ms | 3 ms |
### Priority fixes
1. **largest-contentful-paint** (low) — 2.9 s
2. **first-contentful-paint** (low) — 2.0 s
3. **document-latency-insight** (high) — Est savings of 300 ms
4. **font-display-insight** (high) — Est savings of 50 ms
5. **image-delivery-insight** (high) — Est savings of 187 KiB
### Findings (mobile)
#### Layout-shift sources
- div.grid > div.grid__col > div.double-image-content__content > div.double-image-content__text — shift 0.016
#### DOM size
- Total nodes: 0
#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`
#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.81, weight 25) — Largest Contentful Paint — 2.9 s
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description
### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.
## Security Headers & HTTP
_Captured in 547 ms._
**Transport:**
- Final URL: https://thediplomat.ee/for-business-customers/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/for-business-customers does not redirect to HTTPS (target: http://thediplomat.ee/for-business-customers/)
**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding
**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 96.3 KB
### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/for-business-customers does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare
### Findings
#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)
#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None
#### Info disclosure
- Server: `cloudflare`
#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,9e0e5bfec1050ef71c56af6a046a258f62d4915ea0984ce2147ee481616cd331
cf-cache-status: DYNAMIC
cf-ray: a153c2695eec5423-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:16:05 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,9e0e5bfec1050ef71c56af6a046a258f62d4915ea0984ce2147ee481616cd331
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/58>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=58>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=c94F74Vybtuk5HzXrJGmHqWWPN8wTvPiA%2F8CtCIM0uY2qKYsuOiR0wmttF%2BDDkCZQR58Fg0fO7crShtCYlLn7bcO3mwCjewmw5U8IS7WuxSNA%2FPvvPfqWpcXuDXXKy61"}]}
server: cloudflare
set-cookie: __cf_bm=Zn._l_JJr23wUMaPEIZpymOzLxeAnHRU.HEeRq0Wry4-1783059365.3340917-1.0.1.1-khDkh3dTRsA4.K7oLQt1otIOvsGu2M9O53PEOlugFFeT5i1Ua_iVRGAe5z0pTDeWofdxVjRFG.uCXZKwcUbD0G007BLa87LY3vtKu.2O2PZqnfHXQagBxvg9ZkZjJV.e; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:46:05 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```
### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.
## W3C HTML Validator
_Captured in 673 ms._
**Scoring:** 15 errors · 1 warnings · 46 cosmetic (suppressed)
### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 806
2. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 657
3. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
4. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 531
### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 531 `ible.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 657 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 733 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 806 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`
### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.
## axe-core (Accessibility)
_Captured in 1848 ms._
**Scoring:** 0 violations · 42 passes · critical 0 · serious 0 · moderate 0 · minor 0
### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes
### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).
## Browser Runtime
_Captured in 1854 ms._
**Capture summary:** 0 console events · 0 mixed-content requests · 21 network requests · 415.5 KB total
**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 4 | 340.9 KB |
| font | 2 | 45.9 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |
**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B
**Slowest requests (top 5):**
- https://thediplomat.ee/for-business-customers (document) — 555 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 120 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 120 ms, 0 B
- https://thediplomat.ee/wp-content/uploads/2026/07/img_1905-1440x420.jpeg (image) — 59 ms, 136.5 KB
- https://thediplomat.ee/wp-content/uploads/2026/06/b6480ecc2a0bb9b0278db0e01b0a3cdcb30669f11-960x720.jpg (image) — 56 ms, 78.6 KB
### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.
## HTML Inventory
_Captured in 1854 ms._
**Document:**
- Lang: en
- Title: For business customers - The Diplomat
- Canonical: https://thediplomat.ee/for-business-customers/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 96515
**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none
**Heading outline:**
- Counts: h1 ×1, h2 ×2, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
- h1: For business customers
- h2: Where you don't want to leave. A posting no one dreads.
- h2: Leave a message
**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present
**Scripts:** 38 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.
External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)
**Stylesheets:** 5 external, 3 inline (9.4 KB)
**Images:** 4 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"
Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ediplomat.ee/wp-content/uploads/2026/07/img_1905-120x35.jpeg | _(empty)_ | 120×35 | eager | ✓ |
| diplomat.ee/wp-content/uploads/2026/07/r9a8994-2-100x100.jpg | _(empty)_ | 100×100 | lazy | ✓ |
| 026/06/492590cadf9f94b0c058160cb7fe969b473c10a71-324x432.jpg | _(empty)_ | 324×432 | lazy | ✓ |
| 026/06/b6480ecc2a0bb9b0278db0e01b0a3cdcb30669f11-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |
**Links:** 20 anchors — 4 external, 1 preconnect, 1 preload.
Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2
**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.
## Optimized-Web Checklist
_Captured in 0 ms._
**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a
**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/4 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 23 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |
**Evidence:**
- Page caching plugin / CDN active:
- `HTML markers: WP Rocket`
- `generator: WP Rocket 3.22.0.3`
- `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
- `hero: https://thediplomat.ee/wp-content/uploads/2026/07/img_1905-120x35.jpeg`
- `loading: eager`
- `fetchpriority: (not set)`
- Reasonable number of image sizes:
- `widths: 100, 116, 120, 150, 200, 225, 233, 320, 324, 400, 480, 648, 768, 800, 960, 972, 1152, 1296, 1440, 1536, 1920, 1944, 2880`
### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).