All tools SEO tool · Checklist

Technical SEO audit checklist

Go through the site step by step: mark what is fine and where the issues are, leave notes and get a ready list of fixes sorted by priority.

126 checks in 19 sections report, CSV and PDF progress is saved in your browser
Checked 0 of 1260%
OK
0
Issues
0
N/A
0
Left
126

01 Crawling and indexing

0 / 10
  • robots.txt exists, returns 200 and does not block important sections

    Open /robots.txt. Make sure there is no accidental "Disallow: /" and that CSS, JS and images are not blocked.

    Critical
  • sitemap.xml is valid, up to date and listed in robots.txt

    Only canonical pages with code 200 belong in the sitemap: no redirects, 404s, noindex pages or parameters.

    Critical
  • The site is verified in Google Search Console, the sitemap is submitted

    Use a Domain property so that all protocols and subdomains are covered. Check that the sitemap status is "Success".

    Critical
  • The "Pages" report in GSC has no critical indexing errors

    Review the reasons: "Crawled — currently not indexed", "Duplicate without user-selected canonical", "Soft 404", server errors 5xx.

    Critical
  • Important pages are not closed by noindex or X-Robots-Tag

    Crawl the site (Screaming Frog, Sitebulb) and filter by "noindex". A typical mistake is a noindex left over from the staging version.

    Critical
  • The number of indexed pages matches the real number of useful pages

    Compare: pages in the sitemap, pages found by the crawler and pages indexed in GSC. A big gap means junk in the index or lost pages.

    Important
  • Service and junk pages are closed from indexing

    Site search, cart, checkout, account, sorting, UTM and session parameters, print versions.

    Important
  • Test and dev versions of the site are closed from search engines

    The best protection is HTTP authorisation. Check with the query site:dev.example.com and by subdomains in GSC.

    Critical
  • Server logs are analysed: Googlebot spends the crawl budget on important pages

    Relevant for sites with 10,000+ URLs. Look at which sections the bot visits most often and which it never reaches.

    Recommended
  • All subdomains are accounted for: no forgotten ones that duplicate the main site or sit in the index

    Query site:example.com -inurl:www plus a subdomain search (crt.sh, Ahrefs). Old m., shop., dev. and promo versions are redirected, closed from indexing or kept on purpose.

    Important

02 Mirrors, redirects and response codes

0 / 9
  • One main mirror: http → https and www ↔ non-www with a single 301

    Check all four variants of the home page and an inner page. Each must lead to the main version in one step.

    Critical
  • Trailing slash, letter case and /index.php (.html) are brought to one format

    /page and /page/, /Page and /page, /index.php must not open as separate pages with code 200.

    Important
  • Multiple slashes (//, ///) in the URL are redirected or return 404

    Open example.com///page — the address must not respond with 200 as a duplicate.

    Recommended
  • No redirect chains or loops

    Every redirect leads to the final URL in one hop. Chains of 3+ steps waste crawl budget and slow the page down.

    Important
  • Permanent moves use 301 (308), not 302 or JavaScript / meta refresh

    Temporary 302 redirects that have been in place for months should be replaced with 301.

    Important
  • A non-existent page returns a real 404 (410), not 200 or a redirect to the home page

    Open a random address like /qwerty-12345 and look at the response code. The 404 page should have navigation and a link to the home page.

    Critical
  • No internal links to 404 pages and to redirects

    In the crawler report: Response Codes → Client Error (4xx) and Redirection (3xx) → Inlinks. Replace the links with the final URLs.

    Critical
  • No 5xx server errors during the crawl and in GSC

    GSC → Settings → Crawl stats → By response. Frequent 5xx reduce the crawl rate and drop pages from the index.

    Critical
  • The 404 page is in the site design: navigation, search and links to the main sections

    It helps the visitor stay on the site instead of leaving. The response code must still be 404.

    Recommended

03 Duplicates and canonical

0 / 8
  • Every indexable page has a self-referencing rel=canonical with an absolute URL

    One canonical tag per page, in <head>, in the initial HTML (not added by JavaScript).

    Critical
  • Canonical points to a page with code 200 that is open for indexing

    Canonical to a redirect, 404 or noindex page is ignored by Google. Do not combine canonical to another page with noindex.

    Critical
  • URLs with parameters (sorting, UTM, gclid, session) do not create duplicates

    Such addresses must have a canonical to the clean URL. Internal links should not contain tracking parameters.

    Critical
  • No duplicate title and description across pages

    Crawler report: Page Titles → Duplicate, Meta Description → Duplicate. Most often these are pagination, filters and product variants.

    Important
  • No full or near duplicates of content on different URLs

    One product in several categories with different addresses, identical category texts, copies of pages for different cities with one word changed.

    Important
  • Pagination pages are indexable, have their own canonical and unique title

    Do not put a canonical from page 2, 3… to the first page — Google will stop seeing the products from deeper pages. Add "— page N" to the title.

    Important
  • The canonical chosen by Google matches the one declared on the site

    GSC → URL Inspection → "Google-selected canonical", and the Pages report → "Duplicate, Google chose different canonical than user". A mismatch means Google treats the pages as duplicates.

    Important
  • The first pagination page has no duplicate (?page=1, /page/1), and the category text is not repeated on pages 2, 3…

    ?page=1 should 301 to the category URL. Show the SEO text and the FAQ block on the first page only.

    Important

04 URLs and site structure

0 / 6
  • URLs are human-readable: short, lowercase, hyphens, no IDs and junk

    The address shows what the page is about. No underscores, spaces, Cyrillic or parameters where a static URL is possible.

    Important
  • Important pages are no deeper than 3 clicks from the home page

    Crawler report: Crawl Depth. Pages at depth 5+ are crawled rarely and rank worse.

    Important
  • No orphan pages (pages without internal links)

    Compare the sitemap and GSC data with the list of pages the crawler found by links.

    Important
  • Breadcrumbs are on all inner pages and reflect the real structure

    Every level is a link, the last element is the current page without a link. Marked up with BreadcrumbList.

    Important
  • Navigation is built with regular <a href> links available in HTML

    Menus on onclick, buttons or links that appear only after an interaction are not followed by search bots.

    Critical
  • Each group of queries has its own landing page, there is no cannibalisation

    In GSC check queries for which two or more URLs alternate in search results.

    Recommended

05 Meta tags and headings

0 / 7
  • Every page has a unique, non-empty title up to ~60 characters

    The main query is closer to the beginning. Check: missing, duplicate, too long and too short titles.

    Critical
  • Meta description is filled in, unique, up to ~155 characters

    It does not affect rankings directly, but it affects the snippet CTR. Add a benefit and a call to action.

    Important
  • Exactly one H1 per page, and it differs from the title

    Check pages without H1 and with several H1. The logo and the site name in the header must not be an H1.

    Critical
  • H2–H6 hierarchy is logical, headings are not used for design

    No headings in the menu, footer and sidebars. Levels are not skipped (H2 → H4).

    Recommended
  • Open Graph and Twitter Card tags are set

    og:title, og:description, og:image (1200×630), og:url. Check how the link looks in Telegram and LinkedIn.

    Recommended
  • HTML is valid in critical places: one <head>, lang, UTF-8 charset, viewport

    A broken <head> (for example, a <div> or <img> inside it) makes Google ignore everything below — including canonical and hreflang.

    Recommended
  • Favicon is available to Googlebot and is a multiple of 48 px

    Otherwise Google shows a default globe in the search results instead of your icon.

    Recommended

06 Speed and Core Web Vitals

0 / 9
  • Core Web Vitals are "Good" on field data: LCP ≤ 2.5 s, INP ≤ 200 ms, CLS ≤ 0.1

    Look at real user data: the "Core Web Vitals" report in GSC and the CrUX block in PageSpeed Insights, not only the lab score.

    Critical
  • Server response time (TTFB) is under 0.8 s

    Check several page types: home, category, product, article. Slow TTFB is fixed with caching, a CDN and query optimisation.

    Critical
  • Text compression (Brotli or gzip) and HTTP/2 or HTTP/3 are enabled

    In DevTools → Network look at the content-encoding header and the Protocol column.

    Important
  • Static files are cached in the browser for a long time (Cache-Control)

    Images, CSS, JS and fonts — max-age of a year with a version in the file name or in a parameter.

    Important
  • No render-blocking CSS and JS in <head>; scripts are loaded with defer / async

    Critical CSS is inline or in one small file. Third-party widgets, chats and trackers are loaded after the main content.

    Important
  • The LCP element (main image or heading) loads first: preload, fetchpriority="high", no lazy-load

    PageSpeed Insights shows which element is the LCP. A common mistake is loading="lazy" on the first-screen image.

    Important
  • No layout shifts: images and banners have width / height, fonts use font-display: swap

    Space is reserved for ads, cookie bars and dynamically inserted blocks.

    Important
  • Fonts are in WOFF2, self-hosted, only the needed weights and subsets

    The main text font is preloaded. Each extra weight is another 20–40 KB.

    Recommended
  • A CDN is used for static files (for large or international projects)

    Compare TTFB from different countries (WebPageTest, KeyCDN Performance Test). If the audience and the server are in the same country, a CDN is not required.

    Recommended

07 Mobile version

0 / 4
  • Responsive layout, meta viewport is set, no horizontal scrolling

    Check on a real phone and in DevTools at a width of 360 px.

    Critical
  • The mobile version has the same content, links, meta tags and markup as the desktop one

    Google indexes the mobile version (mobile-first). Text, menu items or structured data hidden on mobile are lost for search.

    Critical
  • Buttons and links are easy to tap (at least 44×44 px), text is 16 px or larger

    Elements are not too close to each other; forms do not zoom the page on focus.

    Important
  • No intrusive pop-ups covering the content on the first screen

    Full-screen banners right after a visit from search are a reason for demotion (intrusive interstitials).

    Important

08 JavaScript and rendering

0 / 5
  • The main content, links and meta tags are present in the source HTML (SSR / prerender)

    Compare "View source" with the rendered DOM. Disable JavaScript and see what remains on the page.

    Critical
  • Google renders the page correctly: URL Inspection → "View tested page"

    Look at the screenshot, the HTML and the list of resources that failed to load.

    Critical
  • Links work without JavaScript: <a href>, not onclick or #hash routes

    In SPAs, every state that should rank needs its own URL through the History API.

    Critical
  • Lazy-loaded content and "Show more" lists are available to the bot

    Googlebot does not scroll or click. Infinite scroll needs paginated URLs with regular links.

    Important
  • No JavaScript errors in the console that break the content or navigation

    DevTools → Console on the main page templates.

    Recommended

09 Structured data

0 / 13
  • Structured data passes the Rich Results Test without errors

    Also look at the "Enhancements" reports in GSC — errors and warnings for each markup type.

    Important
  • Organization / LocalBusiness / Person and WebSite are on the home page

    Name, logo, contacts, sameAs with links to social profiles. This helps both the knowledge panel and AI answers.

    Important
  • BreadcrumbList is on inner pages

    The markup matches the visible breadcrumbs.

    Important
  • Key templates have the right type: Product + Offer, Article, FAQPage, Service, Review

    For products: price, currency, availability, rating. For articles: author, publication and modification dates.

    Important
  • The markup matches the visible content of the page

    Ratings, prices and reviews that the user does not see on the page lead to a manual action.

    Critical
  • Blog posts and news have Article / BlogPosting (NewsArticle) markup

    Fields: headline, image, datePublished, dateModified, author, publisher. The dates match the ones visible on the page.

    Important
  • The article author is marked up as Person and linked to an author page

    In Article.author: name, url of the author page, jobTitle, sameAs (LinkedIn and other profiles). The author page itself has ProfilePage + Person. This is a direct E-E-A-T signal.

    Important
  • Product pages have Product + Offer, and AggregateRating + Review when there are reviews

    In Offer: price, priceCurrency, availability; plus name, image, sku / gtin, brand. Mark up only real reviews that are visible on the page. Add shippingDetails and hasMerchantReturnPolicy for merchant listings.

    Critical
  • Categories and listings have CollectionPage + ItemList

    ItemList contains the items of the current page with position and url. On pagination pages — only the items of that page.

    Important
  • Pages with a question-and-answer block have FAQPage

    Only the questions and answers that are visible on the page. Google now shows the FAQ rich result for few sites, but the markup still helps AI answers parse the content.

    Recommended
  • Service pages have a specific type: AboutPage, ContactPage, WebPage

    About, Contacts, Delivery and payment. Link the page to the site through isPartOf → WebSite and to the company through about / publisher.

    Recommended
  • Self-hosted videos have VideoObject

    Fields: name, description, thumbnailUrl, uploadDate, contentUrl or embedUrl. For YouTube embeds the markup is optional.

    Recommended
  • Key images are marked up: ImageObject or the image property in Article / Product

    Fields: url, width, height, caption. For your own photos add license and creator — they give the "Licensable" badge in Google Images.

    Recommended

10 Language versions and hreflang

0 / 5
  • Each language version has its own URL (folder, subdomain or domain)

    Switching the language through cookies or a parameter without a separate address is not indexed.

    Critical
  • hreflang is reciprocal, includes a self-reference and x-default

    If page A points to B, then B must point to A. Codes follow ISO: uk — the Ukrainian language, ua is not a language code.

    Critical
  • hreflang points to canonical pages with code 200

    No links to redirects, 404 and noindex pages. The canonical of every version points to itself, not to another language.

    Important
  • No forced redirect by IP or browser language

    Googlebot crawls mostly from the USA — with a forced redirect it will never see other versions. Offer the version with a banner instead.

    Important
  • Everything is translated: title, description, H1, alt, URL, interface elements

    The lang attribute of the <html> tag matches the language of the page. No mixed-language pages.

    Important

11 Images and media

0 / 5
  • Images are in WebP / AVIF and compressed

    Crawler report: Images → Over 100 KB. Heavy PNG and JPEG files are the most common cause of a poor LCP.

    Important
  • Image dimensions match the display size, srcset is used for different screens

    A 3000 px photo in a 400 px block wastes traffic and time.

    Important
  • Meaningful images have a descriptive alt

    Describe what is in the picture, without a list of keywords. Decorative images have an empty alt="".

    Important
  • Images below the first screen have loading="lazy"

    Use the native attribute, not a JS library that replaces src with data-src — the bot may not see such images.

    Important
  • No broken images and images blocked in robots.txt

    Crawler report: Images → Response Codes 4xx. Files are served from your domain or a CDN available to bots.

    Important

12 Security and server

0 / 10
  • A valid SSL certificate, the whole site works over HTTPS

    Check the expiry date and automatic renewal. The certificate covers www and all subdomains in use.

    Critical
  • No mixed content: all resources and internal links use https

    Crawler report: Security → Mixed Content, HTTP URLs. Also check canonical, hreflang and the sitemap.

    Important
  • Security headers are set: HSTS, X-Content-Type-Options, Referrer-Policy, CSP

    A quick check — securityheaders.com. HSTS additionally removes the http → https redirect for returning visitors.

    Recommended
  • No manual actions or security issues in GSC

    GSC → Security & Manual Actions. Also check the domain in Google Safe Browsing.

    Critical
  • No signs of hacking: foreign pages in the index, hidden links, redirects for mobile users

    Check the query site:example.com with words like casino, viagra, and Japanese or Chinese characters.

    Critical
  • Uptime is 99.9% or higher, monitoring and backups are set up

    UptimeRobot or a similar service with notifications. Check that a backup can actually be restored.

    Important
  • Users and search bots receive the same content

    Compare the page with a regular User-Agent and with Googlebot. Make sure the firewall, CDN or anti-bot protection does not block real Googlebot.

    Critical
  • The domain and IP are not on blacklists: Google Safe Browsing, antivirus databases, spam lists

    Check the Google Safe Browsing site status (transparencyreport.google.com), VirusTotal and Sucuri SiteCheck, and Spamhaus / MXToolbox for the IP and the mail domain.

    Critical
  • Forms are protected from spam and bots: reCAPTCHA, Turnstile or a honeypot

    Without protection spam leads clog the CRM, and open comment and search forms are used to generate spam pages and links. Load the protection script only when the form is used, so that it does not slow the page down.

    Important
  • The domain history is checked: past content, sanctions, spammy backlinks

    The Web Archive (web.archive.org) shows what used to be on the domain; Ahrefs or Serpstat show the backlink profile and traffic drops. Especially important for a purchased or dropped domain.

    Important

14 E-commerce: filters, catalogue, products

0 / 6
  • Filters are under control: useful combinations are landing pages, the rest are closed

    Filter pages with demand have a static URL, unique title, H1 and are in the sitemap. Combinations of 2–3+ filters are closed from indexing.

    Critical
  • Sorting, view type and items-per-page do not create indexable pages

    Canonical to the page without parameters, or the parameters are closed in robots.txt.

    Important
  • Out-of-stock products are handled correctly

    Temporarily unavailable — code 200 with the status and alternatives. Gone forever — 301 to an analogue or the category, or 410.

    Important
  • Product variants (colour, size) do not create duplicates

    Either one page with a selector, or separate pages with unique content and a canonical to the main variant.

    Important
  • No empty categories and thin pages with 1–2 products in the index

    Empty listings are treated by Google as Soft 404 and lower the overall quality assessment of the site.

    Important
  • Product markup and the Merchant Center feed contain the same prices and availability

    A mismatch leads to disapproved products and the loss of free product listings.

    Recommended

15 AI search and GEO

0 / 5
  • AI crawlers are not blocked by accident: GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended

    Check robots.txt and the firewall / CDN rules (Cloudflare blocks AI bots by default on some plans). Decide deliberately which bots you allow.

    Important
  • Key content is available without JavaScript — most AI bots do not render it

    Prices, characteristics, answers to questions and contacts must be in the source HTML.

    Important
  • Content is structured for citation: a direct answer first, lists, tables, FAQ

    Question-style headings and short self-contained paragraphs are quoted by AI answers more often.

    Recommended
  • Authorship and expertise are visible: author, dates, sources, "About" page

    Person and Organization markup with sameAs links the site with profiles and mentions on other platforms.

    Recommended
  • llms.txt with a short description of the site and links to key pages is added

    It is not a standard yet and gives no guarantees, but it takes ten minutes and does no harm.

    Recommended

16 Analytics and monitoring

0 / 7
  • GA4 (or another analytics system) is installed on all pages and counts conversions

    Crawler → Custom Search for the tag ID: find pages without the code. Check that key events fire (form, purchase, call).

    Critical
  • GSC is linked with GA4; a Bing Webmaster Tools account is created

    Bing data is also used by ChatGPT search and Copilot — the sitemap is worth submitting there too.

    Recommended
  • Position and visibility tracking is set up for the main queries

    Without a "before" snapshot it is impossible to evaluate the effect of the fixes after the audit.

    Important
  • Alerts are set up: traffic drop, growth of 404 / 5xx, changes in robots.txt and noindex

    Email alerts from GSC are on; a scheduled crawl compares the site with the previous version.

    Recommended
  • A repeat audit is scheduled after the fixes and after every release

    Technical errors come back with new features, redesigns and CMS updates. Check monthly, and for large sites — weekly.

    Recommended
  • The GA4 / GTM code is installed once, with no duplicates

    Two tags double the page views and distort engagement and conversion rates. Check with Tag Assistant and in the page source: one GTM container, and GA4 is not installed both directly and through GTM.

    Critical
  • E-commerce and key events are tracked: purchase, add_to_cart, begin_checkout, forms, clicks

    purchase sends transaction_id, value, currency and items with item_id. Place a test order and check it in DebugView; compare the number of orders in GA4 and in the CRM.

    Important

17 Content and page quality

0 / 4
  • No empty pages, stubs or "under construction" pages on the site and in the index

    Crawler → filter by word count (Low Content Pages). Lorem ipsum, test products, empty tag and category pages: fill them in, close with noindex or remove.

    Critical
  • Texts are unique: not copied from other sites or from the manufacturer

    Check key pages with a plagiarism checker (Copyscape) or search for a sentence in quotes. Also check whether other sites have copied your texts.

    Important
  • No hidden text or links: display:none, text in the background colour, off-screen positioning

    Content in tabs and accordions is fine. Text that is hidden from users but left for bots violates the Google spam policies.

    Important
  • No affiliate sites: several sites of one owner with the same products, contacts and content

    Google may show only one of them or treat them as doorways. Look for matching phone numbers, addresses, company details and WHOIS. Merge the sites with 301 redirects or make them really different.

    Important

18 Site functionality

0 / 4
  • All forms, buttons, links and calculators work, and the leads actually arrive

    Send a test request from every form on desktop and on a phone. Check that it reaches the email, CRM or messenger and that the user sees a confirmation.

    Critical
  • The path to a purchase or sign-up is walked through to the end without errors

    Product → cart → checkout → payment → confirmation email. Check in different browsers, on a phone, and both as a guest and as a logged-in user.

    Critical
  • Site search, filters and sorting work correctly

    Search finds products by name, by SKU and with typos; an empty result offers alternatives. Filters do not lead to empty pages and do not reset each other.

    Important
  • The CMS lets you edit the SEO fields on every page type

    Title, description, H1, text, URL, canonical, robots, alt and redirects — for the home page, categories, products, articles and filter pages, plus templates for bulk generation. Without this the audit fixes cannot be implemented.

    Important

19 Regional targeting and local SEO

0 / 4
  • The target country and region are clear to Google: domain or folder, hreflang, currency, address, phone

    A country domain (.ua, .pl) or a country folder with hreflang, the local currency and phone format, the address in the footer and on the contact page. The server location hardly matters.

    Important
  • A Google Business Profile is created, verified and filled in (for a business with an address or a service area)

    The right category, opening hours, photos, a link to the site with a UTM tag. Reviews get answers.

    Important
  • Name, address and phone (NAP) are identical on the site, in LocalBusiness markup, in the Business Profile and in directories

    Different spellings of the address and old phone numbers lower trust in the data. In LocalBusiness: address, geo, openingHoursSpecification, telephone.

    Important
  • Each city or branch has its own page with unique content

    Address, map, local phone, prices and reviews of that branch. Pages that differ only in the city name are doorways.

    Recommended

Found issues and not sure where to start?

Send me the report — I will tell you what really affects traffic and what can wait.

How it works

From the first check to a list of fixes

  1. 01

    Crawl the site

    Run a crawler and open Google Search Console — most of the checks rely on their reports.

  2. 02

    Mark the status

    For each item choose: OK, issue or not applicable. Add a note with example URLs to the issues.

  3. 03

    Take the report

    Copy the list of issues sorted by priority, download a CSV for a task tracker or print it to PDF.

FAQ

Questions about the checklist

Missing an important check? Write to me — I will add it.

Where is my progress saved?

In your browser (localStorage), on this device only. Nothing is sent to the server and no sign-up is needed. To hand the result over, use "Copy the report", CSV export or print to PDF.

What tools do I need for the audit?

Google Search Console, a crawler (Screaming Frog SEO Spider, Sitebulb or Netpeak Spider), PageSpeed Insights, the Rich Results Test and browser DevTools. This is enough for 90% of the checks.

In what order should I fix the issues?

Start with the "Critical" ones: they prevent pages from being crawled and indexed at all. Then "Important" — duplicates, speed, structure. "Recommended" items give a smaller effect and are done last. The report sorts the issues in this order.

How often should a technical audit be done?

A full audit — once every 6–12 months and always before and after a redesign, migration or CMS change. A short check of the critical items — monthly, for large e-commerce sites — weekly.

Eugene Pakharenko
Eugene PakharenkoSEO Expert
Open to interesting projects

Want to talk SEO?

The quickest way to reach me is a message in Telegram or WhatsApp. I am also happy to connect on LinkedIn.