Audit

20260703T061513Z-77b4

← Back to thediplomatee
Audited URL
https://thediplomat.ee/
Timestamp
2026-07-03T06:20:09.785Z
Kind
site
Pages
5
Audit summary
https://thediplomat.ee/
5 of 5 pages audited
Pagespeed scores
Other checks
LLM Report

Weighted audit summary

78
Overall site quality
Needs Improvementhigh confidence

Site overall 78 is the mean of 5 pages. Scores range 74 (https://thediplomat.ee/faq) → 82 (https://thediplomat.ee/). Weakest page: Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.

Per-page scores
82
Home
high
78
/contact
high
74
/faq
high
76
/et/kkk
high
78
/for-business-customers
high

# Audit Report: A place with a character. 
In a neighbourhood that has one too. - The Diplomat

Website: https://thediplomat.ee/
Date: 2026-07-03

Overall Score: 78 / 100
Status: 🟡 Needs Improvement
Confidence: high
Audit Coverage: 100% — all sources returned data

Pages Audited (5 of 5):

Summary

Site overall 78 is the mean of 5 pages. Scores range 74 (https://thediplomat.ee/faq) → 82 (https://thediplomat.ee/). Weakest page: Mobile performance is strong at 88 with excellent TTFB (6 ms), but LCP (3.0 s) exceeds the 2.5 s threshold. Security is the weakest area with a 13/100 header grade and HTTP failing to redirect to HTTPS, which is critical given the site accepts user content. Accessibility has one critical axe violation regarding invalid ARIA values on accordions. SEO is mostly solid but lacks a meta description. Confidence is high as all audit tools returned complete data.

Per-Page Scores

Page Score Status Confidence
https://thediplomat.ee/ 82 🟡 Needs Improvement high
https://thediplomat.ee/contact 78 🟡 Needs Improvement high
https://thediplomat.ee/faq 74 🟡 Needs Improvement high
https://thediplomat.ee/et/kkk 76 🟡 Needs Improvement high
https://thediplomat.ee/for-business-customers 78 🟡 Needs Improvement high

PageSpeed Insights — Mobile vs Desktop

Lower is worse for Performance; higher is worse for LCP and CLS. Worse value is bolded.

URL Performance (M / D) LCP (M / D) CLS (M / D)
https://thediplomat.ee/ 91 / 100 3.16 s / 776 ms 0.012 / 0.000
https://thediplomat.ee/contact 94 / 99 2.75 s / 910 ms 0.010 / 0.000
https://thediplomat.ee/faq 88 / 100 2.96 s / 731 ms 0.000 / 0.000
https://thediplomat.ee/et/kkk 88 / 99 3.05 s / 724 ms 0.000 / 0.001
https://thediplomat.ee/for-business-customers 94 / 99 2.87 s / 873 ms 0.016 / 0.001

Optimization Checklist

4 of 4 passing — 4 pass · 0 warn · 0 fail · 3 n/a

Item Status Detail
Page caching plugin / CDN active Pass Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta
Images lazy-loaded Pass All non-hero raster images use loading="lazy" except one.
Hero image eagerly loaded Pass Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable).
Hero is a real <img> (not a CSS background-image) N/A No CSS background-images detected on raster-image-eligible elements.
Responsive images (srcset / <picture>) N/A Only 2 raster images on the page — responsive-image rule does not apply.
Reasonable number of image sizes N/A Too few raster images to evaluate srcset width variety.
JS scripts not blocking in <head> Pass No render-blocking scripts in <head>.

Fixes

Priority 1: Critical

Immediate action — impacts user experience, search rankings, or site safety.

1A. Add HSTS and Content-Security-Policy headers

  • Impact: Security Headers Grade, XSS/Clickjacking protection
  • Problem: Security Headers grade is 13/100; HSTS and CSP are missing despite site signals indicating user-generated content (upload link).
  • Solution: Add HSTS with preload and a strict CSP:
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic'; object-src 'none'; base-uri 'none';
    

1B. Fix serious color-contrast violation

  • Impact: WCAG 1.4.3 Compliance, Accessibility Score
  • Problem: axe-core reports 1 serious violation on .button--secondary where background and foreground colors lack sufficient contrast.
  • Solution: Increase contrast ratio to at least 4.5:1 for the secondary button text. Use a darker text color or lighter background in CSS.

1C. Enforce HTTPS redirect and add HSTS

  • Impact: Transport security, data integrity

  • Problem: HTTP does not redirect to HTTPS (http://thediplomat.ee/contact stays on HTTP), and HSTS is missing. Security Headers grade is 13/100.

  • Solution: Configure the web server or CDN (Cloudflare) to redirect all HTTP traffic to HTTPS immediately.

    Cloudflare Page Rule:

    • URL: thediplomat.ee/*
    • Setting: Always Use HTTPS

    Apache/Nginx (Origin):

    RewriteCond %{HTTPS} off
    RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    

    Add HSTS Header:

    Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
    

1D. Implement Content Security Policy (CSP)

  • Impact: XSS protection, data exfiltration prevention

  • Problem: CSP is missing. Site signals indicate User-Generated Content (textarea, upload link), making XSS risk high per the security rubric.

  • Solution: Deploy a strict CSP with nonces for scripts. Start with a report-only mode to avoid breaking WP Rocket/CDN scripts.

    Header:

    Header always set Content-Security-Policy "default-src 'self'; script-src 'nonce-{RANDOM}' 'strict-dynamic' https:; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: https:; font-src 'self' https://fonts.gstatic.com; form-action 'self'; frame-ancestors 'self';"
    

    Implementation:

    • Generate a random nonce per request in PHP/WordPress.
    • Add nonce="{NONCE}" to all <script> tags.
    • Monitor Content-Security-Policy-Report-Only before enforcing.

1E. Enforce HTTPS and Add Critical Security Headers

  • Impact: Transport security, XSS protection, clickjacking
  • Problem: HTTP does not redirect to HTTPS, and HSTS/CSP are missing. Site signals indicate User-Generated Content (textarea/upload), making XSS protection critical.
  • Solution: Configure server/CDN to redirect all HTTP traffic to HTTPS. Add the following headers:
    Strict-Transport-Security: max-age=63072000; includeSubDomains; preload
    Content-Security-Policy: default-src 'self'; script-src 'nonce-{random}' 'strict-dynamic';
    X-Frame-Options: SAMEORIGIN
    

1F. Fix Critical ARIA Attribute Values

  • Impact: Accessibility (WCAG 4.1.2)
  • Problem: Critical axe violation: aria-expanded uses value '1' instead of 'true'/'false' on accordion buttons. W3C validator confirms 4 instances of this error.
  • Solution: Update accordion buttons to use boolean strings:
    <button aria-expanded="true" aria-controls="...">
      Toggle Section
    </button>
    

1G. Force HTTPS redirect and add HSTS

  • Impact: Transport security, MITM protection
  • Problem: HTTP does not redirect to HTTPS (http://thediplomat.ee/et/kkk does not redirect) and HSTS is missing, leaving users vulnerable on insecure connections.
  • Solution: Configure the web server (Nginx/Apache) to return 301 redirects for all HTTP traffic to HTTPS. Add HSTS header:
    add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
    

Priority 2: Important

Essential for compliance, user reach, and search visibility.

2A. Optimize Largest Contentful Paint (LCP)

  • Impact: Performance Score, LCP Metric
  • Problem: Mobile LCP is 3.2 s (warning zone), flagged by PSI largest-contentful-paint and image-delivery-insight.
  • Solution:
    • Preload the LCP image resource.
    • Ensure hero image uses fetchpriority="high".
    • Convert remaining heavy images to WebP/AVIF if not already done.

2B. Fix W3C script type/defer errors

  • Impact: HTML Validity, Potential JS Execution Issues
  • Problem: W3C Validator reports 4 errors where script elements with non-standard type attributes (e.g., text/rocketlazyloadscript) incorrectly use the defer attribute.
  • Solution: Update WP Rocket configuration or custom scripts to remove defer from non-standard script types, or change type to text/javascript where appropriate.

2C. Fix W3C Validation Errors (Scripts & ARIA)

  • Impact: Maintainability, Accessibility compliance

  • Problem: 19 W3C errors found, including 11 instances of type="text/rocketlazyloadscript" with defer and 3 invalid aria-expanded="" attributes.

  • Solution:

    1. Scripts: Remove type attribute from standard JS or use valid MIME types (text/javascript). WP Rocket's lazyload script type is non-standard.
    2. ARIA: Fix aria-expanded to be true or false (not empty string).
    3. Hidden Inputs: Remove autocomplete from type="hidden" inputs.

    Example Fix:

    <!-- Before -->
    <button aria-expanded="" ...>
    <!-- After -->
    <button aria-expanded="false" ...>
    

2D. Add Meta Description and Structured Data

  • Impact: SEO, Search Result CTR

  • Problem: PSI SEO audit fails metaDescription and structuredData. HTML Inventory confirms Description is not set.

  • Solution: Add a unique meta description (150-160 chars) in the <head>.

    <meta name="description" content="Contact The Diplomat for inquiries regarding apartments, payments, and general support. Reach out via our secure form.">
    

    Add JSON-LD for ContactPage or LocalBusiness:

    <script type="application/ld+json">
    {
      "@context": "https://schema.org",
      "@type": "ContactPage",
      "name": "Contact The Diplomat"
    }
    </script>
    

2E. Add Meta Description for SEO

  • Impact: SEO (Search Snippets)
  • Problem: W3C and PSI report missing meta description. This affects click-through rates in search results.
  • Solution: Add a concise description (150–160 characters) in the <head>:
    <meta name="description" content="Frequently asked questions about The Diplomat apartments, payments, and move-in process.">
    

2F. Fix W3C validation errors and ARIA attributes

  • Impact: Accessibility, Standards compliance
  • Problem: 19 W3C errors including invalid aria-expanded="1" (should be true/false) and invalid script types with defer attribute.
  • Solution:
    • Update aria-expanded values to boolean strings (true/false).
    • Remove type="text/rocketlazyloadscript" or use valid MIME types for scripts.
    • Fix hidden input autocomplete attributes per W3C spec.

2G. Add Meta Description

  • Impact: SEO, Click-through rate
  • Problem: SEO audit flags metaDescription as missing; document has no description tag.
  • Solution: Add a concise description (150–160 chars) in the <head>:
    <meta name="description" content="Korduma kippuvad küsimused The Diplomat'i teenuste kohta. Leia vastused broneerimise, maksete ja majutuse küsimustele.">
    

2H. Fix W3C HTML Validation Errors

  • Impact: Maintainability, Compliance
  • Problem: 15 errors found, including 11 instances of script with invalid type attributes (WP Rocket) and hidden inputs with autocomplete.
  • Solution:
    • Remove type attribute from standard JS scripts (or use valid MIME types).
    • Remove autocomplete from input type="hidden" elements.
    • Move meta charset to the first 1024 bytes of the document.
    • Fix unclosed <p> tags.

Priority 3: Best Practice

Recommended for long-term maintainability.

3A. Ensure lazy loading for below-fold images

  • Impact: Page Weight, Initial Load Time
  • Problem: HTML Inventory shows 2 images missing loading="lazy" despite being below the fold.
  • Solution: Add loading="lazy" to all <img> tags that are not the LCP element or above the fold.

3B. Optimize LCP and Font Loading

  • Impact: Core Web Vitals (LCP 2.8 s)

  • Problem: Mobile LCP is 2.8 s (warning zone). PSI suggests 80 ms savings from font-display and 142 KiB from image delivery.

  • Solution:

    1. Fonts: Add font-display: swap to CSS or use display=swap in Google Fonts URL.
    2. Images: Ensure the LCP image (likely the hero) is preloaded or has fetchpriority="high" (already present per checklist, verify priority).
    3. Images: Convert remaining raster images to WebP/AVIF if not already done.

    Google Fonts:

    <link href="https://fonts.googleapis.com/css?family=Open+Sans&display=swap" rel="stylesheet">
    

3C. Resolve W3C HTML Validation Errors

  • Impact: Maintainability, Browser Compatibility
  • Problem: 19 errors found, including invalid script types (text/rocketlazyloadscript with defer) and hidden inputs with autocomplete.
  • Solution:
    • Remove defer from non-JavaScript script types (WP Rocket optimization).
    • Remove autocomplete from type="hidden" inputs.
    • Move meta charset to the first 1024 bytes of the document.

3D. Optimize LCP and Image Delivery

  • Impact: Performance (LCP 2.9 s)
  • Problem: LCP is 2.9 s (warning threshold) and PSI suggests 187 KiB savings via image delivery optimization.
  • Solution:
    • Convert remaining JPEGs to WebP/AVIF.
    • Ensure the LCP image (likely the hero) has fetchpriority="high".
    • Preload the LCP image resource in the <head>.
▸Raw Markdown sent to the LLM
# Site Audit — https://thediplomat.ee/
Run: 2026-07-03T06:15:14.168Z

Audited **5** of 5 discovered pages.
Average per-page audit coverage: **100%**

Pages audited:
- https://thediplomat.ee/
- https://thediplomat.ee/contact
- https://thediplomat.ee/faq
- https://thediplomat.ee/et/kkk
- https://thediplomat.ee/for-business-customers

---

# Page 1 of 5 — https://thediplomat.ee/

Run: 2026-07-03T06:15:15.396Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 19342 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **91** | 100 |
| Accessibility | **90** | 96 |
| Best Practices | 100 | 100 |
| SEO | 100 | 100 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.2 s** | 0.8 s |
| CLS | **0.012** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **2.10 s** | 500 ms |
| Speed Index | **2.10 s** | 500 ms |
| TTFB | **6 ms** | 4 ms |

### Priority fixes
1. **largest-contentful-paint** (medium) — 3.2 s
2. **first-contentful-paint** (low) — 2.1 s
3. **font-display-insight** (high) — Est savings of 30 ms
4. **image-delivery-insight** (high) — Est savings of 86 KiB
5. **network-dependency-tree-insight** (high)

### Findings (mobile)

#### Layout-shift sources
- main#main > div.section > div.hero__title-wrapper > div.h-container — shift 0.012

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `color-contrast` (accessibility, score 0.00, weight 7) — Background and foreground colors do not have a sufficient contrast ratio.
- `largest-contentful-paint` (performance, score 0.73, weight 25) — Largest Contentful Paint — 3.2 s
- `first-contentful-paint` (performance, score 0.81, weight 10) — First Contentful Paint — 2.1 s
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 112 ms._

**Transport:**
- Final URL: https://thediplomat.ee/
- Status: 200
- Redirected: false
- HTTPS redirect: HTTP → HTTPS ✓

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: Fri, 03 Jul 2026 06:14:22 GMT
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 125.0 KB

### Priority fixes
1. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
2. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
3. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
4. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
5. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
6. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
7. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
8. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
9. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
age: 53
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cf-cache-status: HIT
cf-ray: a153c1313b15c7e7-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:15 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,d6f37d52171526195ac378710986608eaa33383690ec9b71b230c6afdfd5199d
ki-cache-type: Edge
ki-cf-cache-status: HIT
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
last-modified: Fri, 03 Jul 2026 06:14:22 GMT
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/2>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SuBO1CAavTTwNWUBH%2FrIUtt2rA7JCG6G2WRFoVeh%2FBYTbrCiFtP%2FFFC4MEv4awMvkYG1Uqyt8d9s3PorsXxDxMCi7bibilIaPf8DnLVkYDzTlyvQfvIv6v4G6uivR7hr"}]}
server: cloudflare
set-cookie: __cf_bm=68DmxnkTJoa7.XOuaWFt0ux9IX_v0jF..P3zlvIvYH8-1783059315.3994324-1.0.1.1-sFZvsG7LjmwxPR_jH2Pdst9Z7xJd89lbGHg8qSEemQb5QXEavfd2Of.LIRY22RWLJE3yAZYQHKq6S6tErqHl8fggTpsbp2TRuYnGJpr1ygMb9J5_.E2HYkckU.7nNqCW; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:15 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 725 ms._

**Scoring:** 4 errors · 9 warnings · 40 cosmetic (suppressed)

### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (medium) — x4, first at line 1628

### Issue groups
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 468 `/noscript><script nowprocket type="text/javascript">var el`
- (×6) [warning] Article lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all articles. — first at line 523 `<article class="room-card room-card--display carousel__card">
    <`
- (×1) [warning] Empty heading. — first at line 814 `<h2 class="cta__title h2"></h2>`
- (×4) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 1628 `</script>
<script type="text/rocketlazyloadscript" data-wp-strategy="defer" defe`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1735 ms._

**Scoring:** 2 violations · 41 passes · critical 0 · serious 1 · moderate 0 · minor 1

### Priority fixes
1. **color-contrast** (high) — Elements must meet minimum color contrast ratio thresholds
2. **empty-heading** (low) — Headings should not be empty

### Findings

#### `color-contrast` (serious) — WCAG: wcag2aa, wcag143
[Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright)
- `.button--secondary > .button__inner > .button__text`

#### `empty-heading` (minor)
[Headings should not be empty](https://dequeuniversity.com/rules/axe/4.11/empty-heading?application=playwright)
- `.cta__title`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 10 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1748 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 23 network requests · 546.2 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 7 | 471.6 KB |
| font | 2 | 45.9 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 1 | 0 B |
| other | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 142 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 130 ms, 0 B
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 73 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/pathway-extreme-regular.woff2 (font) — 73 ms, 29.6 KB
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/antonio-bold.woff2 (font) — 73 ms, 16.3 KB

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1748 ms._

**Document:**
- Lang: en
- Title: A place with a character. 
In a neighbourhood that has one too. - The Diplomat
- Canonical: https://thediplomat.ee/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 122543

**Meta tags:**
- Description: This is an example page. It's different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 13 (og:locale, og:type, og:title, og:description, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 8
- hreflang: none
- JSON-LD: 1 blocks (1 valid) — types: Unknown

**Heading outline:**
- Counts: h1 ×1, h2 ×7, h3 ×3, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: A place with a character. 
In a neighbourhood that has one too.
  - h2: At the intersection of calm and central
  - h2: You may also like
  - h2: 
  - h2: Why stay with us?
  - h2: In the neighbourhood
  - h3: The Old Town
  - h3: Bay of Tallinn
  - h3: Downdown & Rotermann
  - h2: Small country, short distances.
  - h2: The Diplomat way

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 22 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 5 external, 3 inline (9.4 KB)

**Images:** 25 total — **0 without alt**, **0 without width/height**, 2 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/e8d4ce07c088fedd0c5f9440ed88c14722cda6ad-320x180.jpg | _(empty)_ | 320×180 | eager | ✓ |
| ://thediplomat.ee/wp-content/uploads/2026/06/501-280x155.jpg | 501.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_2-280x155.jpg | 208_2.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_1-280x155.jpg | 208_1.jpg | 280×155 | lazy | ✓ |
| ://thediplomat.ee/wp-content/uploads/2026/06/505-280x155.jpg | 505.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/208_1-280x155.jpg | 208_1.jpg | 280×155 | lazy | ✓ |
| /thediplomat.ee/wp-content/uploads/2026/06/510_5-280x155.jpg | 510_5.jpg | 280×155 | lazy | ✓ |
| /2026/06/bd904a05d03dd97f3298ab818a9187d1748380cd-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| ediplomat.ee/wp-content/uploads/2026/07/0d3a0784-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/82d207c5f9b11f700807b888b95c3424c15f4d4a-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/85ae5996681b2812414ab3e94020d5e3bbff7ec8-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/297cf245a09f8d821a107c0f6cd2372ebae83b8a-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| hediplomat.ee/wp-content/uploads/2026/07/ext-4-1-320x180.jpg | _(empty)_ | 320×180 | lazy | ✓ |
| 2026/06/34f8e37c0ee3206f9427630e733913d8fbb46ab0-100x100.png | _(empty)_ | 100×100 | lazy | ✓ |
| 2026/06/382f74d29e319e4424ba7bd3e2d3d00f507e22dc-320x180.png | _(empty)_ | 320×180 | lazy | ✓ |

**Links:** 34 anchors — 11 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "get location" ×3
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2
- "+372 5666 9544" ×2

**Forms:**
Form 1:
- text — labeled
- text — labeled

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy" except one. |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 25/25 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 30 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.22.0.3`
  - `CDN: Cloudflare, Kinsta (HIT)`
- Images lazy-loaded:
  - `…p-content/uploads/2026/06/bd904a05d03dd97f3298ab818a9187d1748380cd-120x35.jpg`
- Hero image eagerly loaded:
  - `hero: …-content/uploads/2026/06/e8d4ce07c088fedd0c5f9440ed88c14722cda6ad-320x180.jpg`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Reasonable number of image sizes:
  - `widths: 100, 120, 150, 200, 207, 280, 300, 320, 400, 413, 480, 560, 640, 768, 800, 840, 960, 1024, 1120, 1400, 1440, 1536, 1600, 1680, 1920, 1960, 2048, 2240, 2560, 3200`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 2 of 5 — https://thediplomat.ee/contact

Run: 2026-07-03T06:15:15.398Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 11551 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 99 |
| Accessibility | **94** | 100 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.8 s** | 0.9 s |
| CLS | **0.010** | 0.000 |
| TBT | 0 ms | 0 ms |
| FCP | **1.99 s** | 720 ms |
| Speed Index | **1.99 s** | 720 ms |
| TTFB | 3 ms | **4 ms** |

### Priority fixes
1. **largest-contentful-paint** (low) — 2.8 s
2. **first-contentful-paint** (low) — 2.0 s
3. **document-latency-insight** (high) — Est savings of 470 ms
4. **font-display-insight** (high) — Est savings of 80 ms
5. **image-delivery-insight** (high) — Est savings of 142 KiB

### Findings (mobile)

#### Layout-shift sources
- div.grid > div.grid__col > div.location__box > ul.location__list — shift 0.010

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.84, weight 25) — Largest Contentful Paint — 2.8 s
- `first-contentful-paint` (performance, score 0.84, weight 10) — First Contentful Paint — 2.0 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 588 ms._

**Transport:**
- Final URL: https://thediplomat.ee/contact/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/contact does not redirect to HTTPS (target: http://thediplomat.ee/contact/)

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 101.7 KB

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/contact does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b0c02bd94a32c32031ad1c6aee304445b4e80c3158186a82509219803000316c
cf-cache-status: DYNAMIC
cf-ray: a153c132bc4cc7e7-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:15 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b0c02bd94a32c32031ad1c6aee304445b4e80c3158186a82509219803000316c
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/43>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=43>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=SPhsCfkvzhicY8%2BvlwJRravAGKf7Ip%2FKXXaNREPAU8HVjLqs5zpfJmdGUdP1ECwddiljkcKvPv0mMS%2BpTu3Ag%2Fz3HDYT5ROaafNmGWGhesSp%2BxkOfhhInMtyJFLBQEMl"}]}
server: cloudflare
set-cookie: __cf_bm=R0jBlC1_wM3UcWagTHY783ryqLSXJdCnQUipXWdumVE-1783059315.6393037-1.0.1.1-YRdd9gFkbx6QEjsjXZlt_Ob4wLkjo4uNHf__bUqVB99Mwmdjt2pgubr2JsRAbpwJQ3EYOQnWFN1I_LzQLhHgxTsidg1Q7e07BxI5_.BjQ2fWapgm_bImDJTZN7kLRFnu; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:15 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 779 ms._

**Scoring:** 19 errors · 5 warnings · 47 cosmetic (suppressed)

### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 941
2. **Bad value “” for attribute “aria-expanded” on element “button”.** (medium) — x3, first at line 531
3. **No “p” element in scope but a “p” end tag seen.** (medium) — x2, first at line 462
4. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 764
5. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6

### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×2) [error] No “p” element in scope but a “p” end tag seen. — first at line 462 `llinn</p>
</p>`
- (×3) [error] Bad value “” for attribute “aria-expanded” on element “button”. — first at line 531 `<button
                    aria-controls="accordion-how-do-monthly-payments-and`
- (×3) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 544 `<section
                    aria-labelledby="accordion-how-do-monthly-payments-`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 764 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×2) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 817 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 941 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 2127 ms._

**Scoring:** 0 violations · 42 passes · critical 0 · serious 0 · moderate 0 · minor 0

### Incomplete (axe could not determine)
- [ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright) — 3 nodes
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 2136 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 19 network requests · 421.1 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 316.8 KB |
| font | 3 | 75.7 KB |
| script | 3 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://thediplomat.ee/contact (document) — 636 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 129 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 121 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/fonts/pathway-extreme-semibold.woff2 (font) — 66 ms, 29.8 KB
- https://thediplomat.ee/wp-content/uploads/2026/07/0v2a6253-1-960x720.jpg (image) — 64 ms, 79.8 KB

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 2136 ms._

**Document:**
- Lang: en
- Title: Contact - The Diplomat
- Canonical: https://thediplomat.ee/contact/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 101311

**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×3, h3 ×2, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Contact
  - h2: Seamlessly connected
  - h2: Got a question?
  - h2: Leave a message
  - h3: General
  - h3: Lobby

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 36 total — 3 defer, 0 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)

**Stylesheets:** 5 external, 3 inline (9.4 KB)

**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| thediplomat.ee/wp-content/uploads/2026/07/ext-4-1-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| iplomat.ee/wp-content/uploads/2026/07/0v2a6253-1-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |

**Links:** 22 anchors — 5 external, 1 preconnect, 2 preload.

Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2

**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.22.0.3`
  - `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
  - `hero: https://thediplomat.ee/wp-content/uploads/2026/07/ext-4-1-120x35.jpg`
  - `loading: eager`
  - `fetchpriority: high`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 3 of 5 — https://thediplomat.ee/faq

Run: 2026-07-03T06:15:38.242Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 14617 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **88** | 100 |
| Accessibility | **89** | 94 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.0 s** | 0.7 s |
| CLS | 0.000 | **0.000** |
| TBT | 0 ms | 0 ms |
| FCP | **2.73 s** | 539 ms |
| Speed Index | **4.36 s** | 539 ms |
| TTFB | **6 ms** | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (low) — 3.0 s
2. **first-contentful-paint** (medium) — 2.7 s
3. **speed-index** (low) — 4.4 s
4. **document-latency-insight** (high) — Est savings of 80 ms
5. **font-display-insight** (high) — Est savings of 40 ms

### Findings (mobile)

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `aria-valid-attr-value` (accessibility, score 0.00, weight 10) — `[aria-*]` attributes do not have valid values
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.79, weight 25) — Largest Contentful Paint — 3.0 s
- `first-contentful-paint` (performance, score 0.59, weight 10) — First Contentful Paint — 2.7 s
- `speed-index` (performance, score 0.75, weight 10) — Speed Index — 4.4 s
- `forced-reflow-insight` (performance, score 0.00, weight 0) — Forced reflow
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 587 ms._

**Transport:**
- Final URL: https://thediplomat.ee/faq/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/faq does not redirect to HTTPS (target: http://thediplomat.ee/faq/)

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 97.9 KB

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/faq does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,eabc8c995bffa84a9e3c6a8a383a0b61c78ad1b5d97935c8b1aedb7ebf51e64f
cf-cache-status: DYNAMIC
cf-ray: a153c1c17f20543a-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:38 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,eabc8c995bffa84a9e3c6a8a383a0b61c78ad1b5d97935c8b1aedb7ebf51e64f
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/48>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=48>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=UYqQMsC7KcoMADt8nNfRzSQ2QVHh7pd0eRQJ9qA62L62N9dsKe1g4tYUwkShVNPy4AqpCEUFOSg%2FWsRXm7ej7aHXbfFDFynUG%2BlKMqnLMSgAtO0jxBVEoCmOZAnGj0g8"}]}
server: cloudflare
set-cookie: __cf_bm=7CGcsCkr0t7HRiXiP6bimerMAR1hJQZetbHfDmT_GIQ-1783059338.4769058-1.0.1.1-rr4zUOLXHqj73QaY54dQXByggZ6oj2553IQ169CX9LkGvb44aoGBv2OK5v0xGabXpyDWMyJ0kWDm4ka39EfPQUtM5UuH8NhVnLtJB47CLjDLiXJ.lZhVZJwTALhEsk6g; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:38 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 664 ms._

**Scoring:** 19 errors · 5 warnings · 45 cosmetic (suppressed)

### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 863
2. **Bad value “1” for attribute “aria-expanded” on element “button”.** (medium) — x4, first at line 464
3. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 714
4. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 588

### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×4) [error] Bad value “1” for attribute “aria-expanded” on element “button”. — first at line 464 `<button
                    aria-controls="accordion-how-do-monthly-payments-and`
- (×4) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 477 `<section
                    aria-labelledby="accordion-how-do-monthly-payments-`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 588 `ther.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 714 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 790 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 863 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1976 ms._

**Scoring:** 1 violations · 42 passes · critical 1 · serious 0 · moderate 0 · minor 0

### Priority fixes
1. **aria-valid-attr-value** (high) — ARIA attributes must conform to valid values

### Findings

#### `aria-valid-attr-value` (critical) — WCAG: wcag2a, wcag412
[ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright)
- `#accordion-how-do-monthly-payments-and-fees-work-header`
- `#accordion-can-i-get-a-tour-of-the-room-header`
- `#accordion-how-does-move-in-process-work-header`
- `#accordion-can-i-sign-an-agreement-for-any-period-i-wish-header`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1983 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 19 network requests · 264.2 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 159.9 KB |
| font | 3 | 75.7 KB |
| script | 3 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://thediplomat.ee/faq (document) — 561 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 135 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 124 ms, 0 B
- https://thediplomat.ee/wp-content/uploads/2026/06/448c466d69b387f3b2c785f81292ebb76b046a791-960x720.jpg (image) — 66 ms, 81.1 KB
- https://thediplomat.ee/wp-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-1440x420.jpg (image) — 62 ms, 78.8 KB

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1983 ms._

**Document:**
- Lang: en
- Title: FAQ - The Diplomat
- Canonical: https://thediplomat.ee/faq/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 97643

**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Frequently asked questions
  - h2: Didn’t find an answer?

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 36 total — 3 defer, 0 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)

**Stylesheets:** 5 external, 3 inline (9.4 KB)

**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| 026/06/448c466d69b387f3b2c785f81292ebb76b046a791-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |

**Links:** 20 anchors — 4 external, 1 preconnect, 2 preload.

Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2

**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded with fetchpriority="high" (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.22.0.3`
  - `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
  - `hero: …-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg`
  - `loading: eager`
  - `fetchpriority: high`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 4 of 5 — https://thediplomat.ee/et/kkk

Run: 2026-07-03T06:15:46.323Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 12345 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **88** | 99 |
| Accessibility | **89** | 94 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **3.1 s** | 0.7 s |
| CLS | 0.000 | **0.001** |
| TBT | 0 ms | 0 ms |
| FCP | **2.90 s** | 724 ms |
| Speed Index | **3.27 s** | 724 ms |
| TTFB | 4 ms | **20 ms** |

### Priority fixes
1. **largest-contentful-paint** (low) — 3.1 s
2. **first-contentful-paint** (medium) — 2.9 s
3. **document-latency-insight** (high) — Est savings of 240 ms
4. **font-display-insight** (high) — Est savings of 40 ms
5. **image-delivery-insight** (medium) — Est savings of 65 KiB

### Findings (mobile)

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `aria-valid-attr-value` (accessibility, score 0.00, weight 10) — `[aria-*]` attributes do not have valid values
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.76, weight 25) — Largest Contentful Paint — 3.1 s
- `first-contentful-paint` (performance, score 0.53, weight 10) — First Contentful Paint — 2.9 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 658 ms._

**Transport:**
- Final URL: https://thediplomat.ee/et/kkk/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/et/kkk does not redirect to HTTPS (target: http://thediplomat.ee/et/kkk/)

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 97.2 KB

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/et/kkk does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b27fe97603901a9385b4cab5adafb1e0271ed6d6d2ff9c557a7f569ae7997240
cf-cache-status: DYNAMIC
cf-ray: a153c1f46d907123-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:15:46 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,b27fe97603901a9385b4cab5adafb1e0271ed6d6d2ff9c557a7f569ae7997240
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/et/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/et/wp-json/wp/v2/pages/134>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/et/?p=134>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=XSb%2FfKEWO1PRsy3umBT7%2BvR6SRd60AI3H6sGzJiHIIAYopQxDP6FepuWDmOHrHmZILukLAcEr8BB0EU%2BUfVUQUTuBMP%2FiHhhV%2FS1dbfnoC8tdebcZH%2BFmXSCKDMhc%2BfH"}]}
server: cloudflare
set-cookie: __cf_bm=nGMu9tgmjZowiv30VHceFyvrsz0tqA5tW4BM4wF5FbE-1783059346.622395-1.0.1.1-zIV93069w31rUMkdI_aF.8oLcfycQXl2_ngNiFS4rZoj9cfC5A_x4YdtI95HYxRkrvkd4ehmaUXAoQHE2U_54AZt1Oi0dE_frKZ59AVP.3A8oNqBJvu28ynu01l_8_dN; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:45:46 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 1023 ms._

**Scoring:** 19 errors · 5 warnings · 45 cosmetic (suppressed)

### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 847
2. **Bad value “1” for attribute “aria-expanded” on element “button”.** (medium) — x4, first at line 464
3. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 714
4. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
5. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 588

### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×4) [error] Bad value “1” for attribute “aria-expanded” on element “button”. — first at line 464 `<button
                    aria-controls="accordion-kuidas-igakuised-maksed-ja-`
- (×4) [warning] Section lacks heading. Consider using “h2”-“h6” elements to add identifying headings to all sections, or else use a “div” element instead for any cases where no heading is needed. — first at line 477 `<section
                    aria-labelledby="accordion-kuidas-igakuised-maksed-`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 588 `duse.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 714 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 790 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 847 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1932 ms._

**Scoring:** 1 violations · 42 passes · critical 1 · serious 0 · moderate 0 · minor 0

### Priority fixes
1. **aria-valid-attr-value** (high) — ARIA attributes must conform to valid values

### Findings

#### `aria-valid-attr-value` (critical) — WCAG: wcag2a, wcag412
[ARIA attributes must conform to valid values](https://dequeuniversity.com/rules/axe/4.11/aria-valid-attr-value?application=playwright)
- `#accordion-kuidas-igakuised-maksed-ja-tasud-toimivad-header`
- `#accordion-kas-ma-saan-ruumi-naha-enne-broneerimist-header`
- `#accordion-kuidas-sissekolimine-toimub-header`
- `#accordion-kas-saan-solmida-lepingu-endale-sobivaks-perioodiks-header`

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1939 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 20 network requests · 264.2 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 2 | 159.9 KB |
| font | 3 | 75.7 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://thediplomat.ee/et/kkk (document) — 563 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 127 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 121 ms, 0 B
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (script) — 46 ms, 0 B
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (script) — 30 ms, 0 B

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1938 ms._

**Document:**
- Lang: et
- Title: KKK - The Diplomat
- Canonical: https://thediplomat.ee/et/kkk/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 96887

**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×1, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: Korduma kippuvad küsimused
  - h2: Ei saanud vastust oma küsimusele?

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 39 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 5 external, 3 inline (9.4 KB)

**Images:** 2 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| 2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg | _(empty)_ | 120×35 | eager | ✓ |
| 026/06/448c466d69b387f3b2c785f81292ebb76b046a791-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |

**Links:** 18 anchors — 2 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "korterid" ×2
- "naabruses" ×2
- "kkk" ×2
- "kontakt" ×2

**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 4 pass · 0 warn · 0 fail · 3 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | – n/a | Only 2 raster images on the page — responsive-image rule does not apply. |
| Reasonable number of image sizes | – n/a | Too few raster images to evaluate srcset width variety. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.22.0.3`
  - `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
  - `hero: …-content/uploads/2026/06/3325cce1928adbe5bed0ec567ef54334c65382761-120x35.jpg`
  - `loading: eager`
  - `fetchpriority: (not set)`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).

---

# Page 5 of 5 — https://thediplomat.ee/for-business-customers

Run: 2026-07-03T06:16:05.077Z

## Audit Coverage
**100%** of audit sources returned data.

_All sources OK._

## Methodology

Each tool below contributes data to a single overall 0–100 site quality score. Performance dominates the weighting (~40%), followed by accessibility (~30%), image assets (~15%), and SEO/security (~15%). These weights are informative — the score is judged holistically, not from a fixed formula.

Severity scale in `priorities[]`:
- **high** — blocking issue / vulnerability / fail.
- **medium** — significant degradation.
- **low** — minor improvement.

Each tool section below lists: scores → priority fixes → findings → manual checks the tool cannot verify.

## Site Signals (inferred)

Heuristic site-shape signals derived from the audit data. Use these to calibrate the priority of security-header recommendations (see system rubric). Override when the evidence is clearly wrong.

- Auth surface: no
- Payments: no
- User-generated content: **yes** — <textarea> in a form; anchor href contains "upload"
- E-commerce: no

## PageSpeed Insights
_Captured in 11925 ms (mobile + desktop in parallel)._

**Lighthouse scores (mobile vs desktop; worse value bolded):**
| Category | Mobile | Desktop |
| --- | --- | --- |
| Performance | **94** | 99 |
| Accessibility | **94** | 100 |
| Best Practices | 100 | 100 |
| SEO | 92 | 92 |

**Core Web Vitals — lab (Lighthouse) / field (CrUX p75); worse lab value bolded:**
| Metric | Mobile | Desktop |
| --- | --- | --- |
| LCP | **2.9 s** | 0.9 s |
| CLS | **0.016** | 0.001 |
| TBT | 0 ms | 0 ms |
| FCP | **1.96 s** | 551 ms |
| Speed Index | **1.96 s** | 551 ms |
| TTFB | 3 ms | 3 ms |

### Priority fixes
1. **largest-contentful-paint** (low) — 2.9 s
2. **first-contentful-paint** (low) — 2.0 s
3. **document-latency-insight** (high) — Est savings of 300 ms
4. **font-display-insight** (high) — Est savings of 50 ms
5. **image-delivery-insight** (high) — Est savings of 187 KiB

### Findings (mobile)

#### Layout-shift sources
- div.grid > div.grid__col > div.double-image-content__content > div.double-image-content__text — shift 0.016

#### DOM size
- Total nodes: 0

#### Failing modeled audits
- SEO: `metaDescription`
- SEO: `tapTargets`
- SEO: `structuredData`

#### All failing PSI audits (sorted by weight × failure margin)
- `button-name` (accessibility, score 0.00, weight 10) — Buttons do not have an accessible name
- `largest-contentful-paint` (performance, score 0.81, weight 25) — Largest Contentful Paint — 2.9 s
- `first-contentful-paint` (performance, score 0.85, weight 10) — First Contentful Paint — 2.0 s
- `lcp-discovery-insight` (performance, score 0.00, weight 0) — LCP request discovery
- `network-dependency-tree-insight` (performance, score 0.00, weight 0) — Network dependency tree
- `meta-description` (seo, score 0.00, weight 1) — Document does not have a meta description

### Manual checks
- Real-device behavior on slow 3G / low-tier mobile hardware (Lighthouse is throttled simulation).
- Sustained INP under typical user interaction, not just initial load.
- CrUX data interpretation if site is low-traffic and field data falls back to origin or is missing.

## Security Headers & HTTP
_Captured in 547 ms._

**Transport:**
- Final URL: https://thediplomat.ee/for-business-customers/
- Status: 200
- Redirected: false
- HTTPS redirect: ✗ http://thediplomat.ee/for-business-customers does not redirect to HTTPS (target: http://thediplomat.ee/for-business-customers/)

**Caching:**
- cache-control: `public, max-age=0, s-maxage=86400`
- etag: n/a
- last-modified: n/a
- expires: n/a
- pragma: n/a
- vary: Accept-Encoding

**Compression:**
- content-encoding: br
- content-length: n/a
- Decoded body: 96.3 KB

### Priority fixes
1. **HTTP does not redirect to HTTPS** (high) — http://thediplomat.ee/for-business-customers does not redirect to HTTPS
2. **strict-transport-security missing** (high) — Add HSTS with max-age >= 1 year, includeSubDomains, and preload
3. **content-security-policy missing** (high) — Add a CSP with default-src and script-src restrictions
4. **x-frame-options missing** (medium) — Prefer CSP frame-ancestors; X-Frame-Options as fallback
5. **referrer-policy missing** (low) — Set a Referrer-Policy such as strict-origin-when-cross-origin
6. **permissions-policy missing** (low) — Declare Permissions-Policy to disable unused features
7. **cross-origin-opener-policy missing** (low) — Set COOP to same-origin to isolate browsing context
8. **cross-origin-resource-policy missing** (low) — Set CORP to same-origin or same-site to prevent cross-origin reads
9. **x-permitted-cross-domain-policies missing** (low) — Set to none to prevent Flash/PDF cross-domain requests
10. **server header discloses technology** (low) — Server: cloudflare

### Findings

#### Tracked headers
- **strict-transport-security** (missing, high)
- **content-security-policy** (missing, high)
- **x-frame-options** (missing, medium)
- **x-content-type-options** (present, medium) `nosniff`
- **referrer-policy** (missing, low)
- **permissions-policy** (missing, low)
- **cross-origin-opener-policy** (missing, low)
- **cross-origin-resource-policy** (missing, low)
- **x-permitted-cross-domain-policies** (missing, low)

#### Cookies
- __cf_bm — HttpOnly=true, Secure=true, SameSite=None

#### Info disclosure
- Server: `cloudflare`


#### All response headers
```
alt-svc: h3=":443"; ma=86400
cache-control: public, max-age=0, s-maxage=86400
cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,9e0e5bfec1050ef71c56af6a046a258f62d4915ea0984ce2147ee481616cd331
cf-cache-status: DYNAMIC
cf-ray: a153c2695eec5423-TLL
connection: keep-alive
content-encoding: br
content-type: text/html; charset=UTF-8
date: Fri, 03 Jul 2026 06:16:05 GMT
ki-cache-tag: b3fff9b2-d677-4c7a-9a95-ff6255a8a34e,9e0e5bfec1050ef71c56af6a046a258f62d4915ea0984ce2147ee481616cd331
ki-cache-type: None
ki-cf-cache-status: SAVING
ki-edge: v=28.4.3;mv=99.9.9
ki-origin: o1i
link: <https://thediplomat.ee/wp-json/>; rel="https://api.w.org/", <https://thediplomat.ee/wp-json/wp/v2/pages/58>; rel="alternate"; title="JSON"; type="application/json", <https://thediplomat.ee/?p=58>; rel=shortlink
nel: {"report_to":"cf-nel","success_fraction":0.01,"max_age":604800}
report-to: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=c94F74Vybtuk5HzXrJGmHqWWPN8wTvPiA%2F8CtCIM0uY2qKYsuOiR0wmttF%2BDDkCZQR58Fg0fO7crShtCYlLn7bcO3mwCjewmw5U8IS7WuxSNA%2FPvvPfqWpcXuDXXKy61"}]}
server: cloudflare
set-cookie: __cf_bm=Zn._l_JJr23wUMaPEIZpymOzLxeAnHRU.HEeRq0Wry4-1783059365.3340917-1.0.1.1-khDkh3dTRsA4.K7oLQt1otIOvsGu2M9O53PEOlugFFeT5i1Ua_iVRGAe5z0pTDeWofdxVjRFG.uCXZKwcUbD0G007BLa87LY3vtKu.2O2PZqnfHXQagBxvg9ZkZjJV.e; HttpOnly; SameSite=None; Secure; Path=/; Domain=thediplomat.ee; Expires=Fri, 03 Jul 2026 06:46:05 GMT
transfer-encoding: chunked
vary: Accept-Encoding
x-content-type-options: nosniff
x-edge-location-klb: 1
x-kinsta-cache: HIT
```

### Manual checks
- Cookie attributes set via JavaScript (not visible in HTTP response).
- CORS preflight behavior under non-GET methods (only GET response headers checked).
- HSTS preload list inclusion (check hstspreload.org).
- WAF / DDoS posture beyond what static headers reveal.

## W3C HTML Validator
_Captured in 673 ms._

**Scoring:** 15 errors · 1 warnings · 46 cosmetic (suppressed)

### Priority fixes
1. **A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute.** (high) — x11, first at line 806
2. **An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”.** (medium) — x2, first at line 657
3. **A “charset” attribute on a “meta” element found after the first 1024 bytes.** (medium) — x1, first at line 6
4. **No “p” element in scope but a “p” end tag seen.** (medium) — x1, first at line 531

### Issue groups
- (×1) [error] A “charset” attribute on a “meta” element found after the first 1024 bytes. — first at line 6 `charset="utf-8"><script>if(na`
- (×1) [error] No “p” element in scope but a “p” end tag seen. — first at line 531 `ible.</p>
</p>`
- (×2) [error] An “input” element with a “type” attribute whose value is “hidden” must not have an “autocomplete” attribute whose value is “on” or “off”. — first at line 657 `<input type='hidden' autocomplete='off' class='gform_hidden h-hidden' name='gfor`
- (×1) [warning] The “type” attribute is unnecessary for JavaScript resources. — first at line 733 `/noscript><script nowprocket type="text/javascript">var el`
- (×11) [error] A “script” element with a “type” attribute whose value is neither a JavaScript MIME type, “module”, “importmap”, nor “speculationrules” (i.e., a data block) must not have a “defer” attribute. — first at line 806 `<script type="text/rocketlazyloadscript" id="wp-dom-ready-js" data-rocket-src="h`

### Manual checks
- Whether each `<section>` / `<article>` wraps semantically meaningful content.
- Language tag accuracy for multi-language pages or quoted content.
- Whether structural choices align with the document outline algorithm in screen readers.

## axe-core (Accessibility)
_Captured in 1848 ms._

**Scoring:** 0 violations · 42 passes · critical 0 · serious 0 · moderate 0 · minor 0

### Incomplete (axe could not determine)
- [Elements must meet minimum color contrast ratio thresholds](https://dequeuniversity.com/rules/axe/4.11/color-contrast?application=playwright) — 8 nodes

### Manual checks
- Keyboard-only navigation flow + visible focus indicators on every interactive element.
- Screen reader output (NVDA, VoiceOver) for actual auditory experience.
- Modal focus trapping and restoration on close.
- Touch target sizes (44×44 px minimum per WCAG 2.5.8).
- Color contrast for elements with alpha-transparency or gradients (axe skips these).

## Browser Runtime
_Captured in 1854 ms._

**Capture summary:** 0 console events · 0 mixed-content requests · 21 network requests · 415.5 KB total

**Network bytes by resource type:**
| Type | Count | Bytes |
| --- | --- | --- |
| image | 4 | 340.9 KB |
| font | 2 | 45.9 KB |
| script | 4 | 13.2 KB |
| stylesheet | 5 | 7.7 KB |
| xhr | 3 | 7.7 KB |
| document | 2 | 0 B |
| other | 1 | 0 B |

**Third-party origins (by bytes):**
- https://cdn.jsdelivr.net — 6 requests, 28.6 KB
- https://fonts.googleapis.com — 2 requests, 0 B

**Slowest requests (top 5):**
- https://thediplomat.ee/for-business-customers (document) — 555 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (stylesheet) — 120 ms, 0 B
- https://fonts.googleapis.com/css?family=Open%20Sans%3A400%2C400i%2C600%2C700%2C700i&subset=cyrillic&display=swap (xhr) — 120 ms, 0 B
- https://thediplomat.ee/wp-content/uploads/2026/07/img_1905-1440x420.jpeg (image) — 59 ms, 136.5 KB
- https://thediplomat.ee/wp-content/uploads/2026/06/b6480ecc2a0bb9b0278db0e01b0a3cdcb30669f11-960x720.jpg (image) — 56 ms, 78.6 KB

### Manual checks
- Console output during user interaction (load-only capture).
- Behavior on slow networks and constrained devices.
- WebGL / canvas FPS profiling via DevTools Layers panel.
- Service worker / cache behavior on repeat visits.

## HTML Inventory
_Captured in 1854 ms._

**Document:**
- Lang: en
- Title: For business customers - The Diplomat
- Canonical: https://thediplomat.ee/for-business-customers/
- Viewport: width=device-width, initial-scale=1
- Charset: UTF-8
- HTML bytes: 96515

**Meta tags:**
- Description: not set
- Robots: index, follow, max-snippet:-1, max-video-preview:-1, max-image-preview:large
- Theme color: #ffffff
- Open Graph tags: 12 (og:locale, og:type, og:title, og:url, og:site_name, og:updated_time, og:image, og:image:secure_url, og:image:width, og:image:height, og:image:alt, og:image:type)
- Twitter tags: 5
- hreflang: none
- JSON-LD: none

**Heading outline:**
- Counts: h1 ×1, h2 ×2, h3 ×0, h4 ×0, h5 ×0, h6 ×0
- Sequence (first 20):
  - h1: For business customers
  - h2: Where you don't want to leave. A posting no one dreads.
  - h2: Leave a message

**Landmarks:**
- nav: present
- main: present
- header: present
- footer: present
- Skip-to-content link: present

**Scripts:** 38 total — 3 defer, 1 async, 0 render-blocking. Speculation rules: yes.

External scripts (first 15):
- https://cdn.jsdelivr.net/gh/orestbida/iframemanager@1.3.0/dist/iframemanager.js (defer)
- https://cdn.jsdelivr.net/gh/orestbida/cookieconsent@3.0.1/dist/cookieconsent.umd.js (defer)
- https://thediplomat.ee/wp-content/themes/diplomat/inc/theme/js/core.47581dd6af532b86.js (defer)
- https://thediplomat.ee/wp-content/plugins/wp-rocket/assets/js/wpr-beacon.min.js (async)

**Stylesheets:** 5 external, 3 inline (9.4 KB)

**Images:** 4 total — **0 without alt**, **0 without width/height**, 1 without loading="lazy"

Image inventory (first 15):
| src | alt | w×h | loading | srcset |
| --- | --- | --- | --- | --- |
| ediplomat.ee/wp-content/uploads/2026/07/img_1905-120x35.jpeg | _(empty)_ | 120×35 | eager | ✓ |
| diplomat.ee/wp-content/uploads/2026/07/r9a8994-2-100x100.jpg | _(empty)_ | 100×100 | lazy | ✓ |
| 026/06/492590cadf9f94b0c058160cb7fe969b473c10a71-324x432.jpg | _(empty)_ | 324×432 | lazy | ✓ |
| 026/06/b6480ecc2a0bb9b0278db0e01b0a3cdcb30669f11-320x240.jpg | _(empty)_ | 320×240 | lazy | ✓ |

**Links:** 20 anchors — 4 external, 1 preconnect, 1 preload.

Vague repeated link text:
- "apartments" ×2
- "neighbourhood" ×2
- "faq" ×2
- "contact" ×2

**Forms:**
Form 1:
- text — labeled
- email — labeled
- textarea — labeled
- checkbox — labeled
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**
- hidden — **no label**

### Manual checks
- Visual rendering of detected mojibake (browser may auto-correct for display).
- Whether decorative images correctly use empty `alt=""` (vs. content images missing it).
- Whether headings reflect actual document hierarchy semantically.
- Whether vague link text is disambiguated by `aria-label` or surrounding context.

## Optimized-Web Checklist
_Captured in 0 ms._

**Summary:** 6 pass · 0 warn · 0 fail · 1 n/a

**Checklist:**
| Item | Status | Detail |
| --- | --- | --- |
| Page caching plugin / CDN active | ✓ pass | Caching plugin detected (WP Rocket) + CDN Cloudflare/Kinsta |
| Images lazy-loaded | ✓ pass | All non-hero raster images use loading="lazy". |
| Hero image eagerly loaded | ✓ pass | Hero image is eagerly loaded (inferred from DOM order/size — Lighthouse LCP element unavailable). |
| Hero is a real <img> (not a CSS background-image) | – n/a | No CSS background-images detected on raster-image-eligible elements. |
| Responsive images (srcset / <picture>) | ✓ pass | 4/4 raster images use srcset or <picture> (100%). |
| Reasonable number of image sizes | ✓ pass | 23 distinct srcset widths. |
| JS scripts not blocking in <head> | ✓ pass | No render-blocking scripts in <head>. |

**Evidence:**
- Page caching plugin / CDN active:
  - `HTML markers: WP Rocket`
  - `generator: WP Rocket 3.22.0.3`
  - `CDN: Cloudflare, Kinsta (DYNAMIC)`
- Hero image eagerly loaded:
  - `hero: https://thediplomat.ee/wp-content/uploads/2026/07/img_1905-120x35.jpeg`
  - `loading: eager`
  - `fetchpriority: (not set)`
- Reasonable number of image sizes:
  - `widths: 100, 116, 120, 150, 200, 225, 233, 320, 324, 400, 480, 648, 768, 800, 960, 972, 1152, 1296, 1440, 1536, 1920, 1944, 2880`

### Manual checks
- Cart / checkout / logged-in pages must bypass the page cache or load dynamic regions via AJAX.
- Verify the cache is warmed for the canonical URL on initial deploy (first visitor should not pay the cold-start cost).
- Inspect "hero" image visually — heuristic above picks the first/largest <img>, which may not match the actual LCP element on JS-heavy pages.
- Confirm scripts marked as defer/async actually tolerate deferred execution (some legacy snippets break when reordered).