Website Audit Checklist: 66 Points to Check in 2026
Work through 66 website audit checks covering SEO, technical, content, UX, security and performance, with a separate 50-check PDF and four blank Markdown templates.
Published by AuditWeb
A website audit checklist turns an overwhelming process into a manageable, repeatable system. Without one, you will either miss critical checks or spend hours going back and forth between tools trying to remember what you have and have not examined.
This checklist covers 66 checkpoints across six dimensions: SEO, technical infrastructure, content quality, user experience, security, and performance. It is a working framework for reviewing a website; the agreed scope determines which checks apply to a professional audit.
Work through each section methodically. For each item, check whether it passes, fails, or needs further investigation. Not every checkpoint will apply to every site — skip items that are not relevant to your setup (such as hreflang checks on a single-language site). The goal is thoroughness, not blind compliance.
SEO Checklist
- Each indexable page has a descriptive title — Inspect distinctive page purpose and rendered results. Google truncates titles by available display width rather than a fixed character count and may generate title links from other page signals.
- Important pages have useful meta descriptions — Write concise page-specific summaries but verify actual snippets because Google may select page text that better matches a query.
- Every page has exactly one H1 tag — The H1 should clearly state what the page is about. Multiple H1s confuse the content hierarchy. Zero H1s leave search engines guessing about your primary topic.
- Heading hierarchy is logical (H1 then H2 then H3) — Skipping heading levels (H1 to H3 with no H2) creates a broken content outline. Search engines use heading structure to understand topic relationships within the page.
- Target keyword appears in URL, title, H1, and first 100 words — These four placements signal strong topical relevance. Missing any one of them weakens the page's ability to rank for its target term.
- Images have appropriate text alternatives — Meaningful images need alternatives that serve their purpose; decorative images normally use an empty
alt. Judge the page context instead of filling every attribute with keywords. - Internal links use descriptive anchor text — Anchor text tells search engines what the linked page is about. Generic anchors like "click here" or "read more" pass less topical relevance than descriptive phrases.
- Intended pages have crawlable internal paths — Compare crawl URLs with sitemaps, analytics and search reports to find pages that lack internal links. Add a relevant user-facing path where the page belongs in the site.
- Canonical signals are correctly implemented — For duplicate or near-duplicate URL groups, compare redirects, canonical elements, sitemap inclusion and internal links. Inspect Google's selected canonical on representative URLs.
- XML sitemap exists, is valid, and is submitted to Search Console — Your sitemap should list only indexable, 200-status, canonical URLs. Verify it is referenced in robots.txt and submitted in both Google Search Console and Bing Webmaster Tools.
- Robots.txt is correctly configured — Verify that no important pages or resources are blocked. Test with the robots.txt tester in Search Console.
- Structured data is implemented and validates without errors — Test every schema type on your site with the Rich Results Test. Fix missing required properties, incorrect data types, and deprecated markup.
- No keyword cannibalisation across pages — Two pages targeting the same keyword split ranking authority between them and often result in neither ranking well. Identify overlaps using Search Console's Performance report filtered by query.
When the checks point to a search visibility problem, the SEO audit report guide explains how to turn observations into an interpreted deliverable.
Technical Checklist
- HTTP status matches URL intent — Classify 2xx, redirects, 4xx and 5xx responses. A removed URL without a relevant replacement can correctly return 404 or 410; a permanent move should reach its relevant destination.
- Avoidable redirect chains are removed — Trace every hop and fix loops. Update owned internal links and rules to the final destination while preserving redirects needed for migrations and external requests.
- No redirect loops — A redirect loop (page A redirects to B, which redirects back to A) creates an infinite loop that makes the page inaccessible. Crawl tools flag these automatically.
- HTTPS is enforced sitewide with 301 redirects from HTTP — Every HTTP URL should redirect to its HTTPS equivalent. Test the four variations of your homepage (http, https, www, non-www) and verify they all resolve to one canonical URL.
- SSL certificate is valid and covers all subdomains — An expired or misconfigured certificate triggers browser warnings that destroy user trust and may trigger Google Safe Browsing flags. Test with Qualys SSL Labs.
- No mixed content (HTTP resources on HTTPS pages) — Loading images, scripts, or stylesheets over HTTP on an HTTPS page triggers browser security warnings. Scan for mixed content using Screaming Frog's Insecure Content report.
- Server response time is measured by location and cache state — TTFB includes connection and origin delay. Trace the timing before assigning a server, database or caching cause.
- Priority pages have clear crawlable paths — Run a crawl with depth analysis and investigate deep or orphaned pages in the context of the site's navigation. No universal click count guarantees indexing.
- No duplicate content across URLs — Parameter-based URLs, www vs non-www, trailing slash vs non-trailing slash, and HTTP vs HTTPS can all create duplicate versions. Canonicals and redirects should consolidate them.
- Hreflang tags are correct (multi-language sites) — Every hreflang tag must have a reciprocal tag on the target page. Language and country codes must use the correct ISO format. Self-referencing hreflang tags must be present.
- Pagination is handled correctly — Paginated series should use self-referencing canonical tags on each page (not canonical to page 1) and include clear navigation links between pages.
- JavaScript-rendered content is indexable — If your site uses client-side JavaScript rendering, verify with the URL Inspection tool in Search Console that Google can see your rendered content.
- No broken external links — Outbound links to pages that return 404 or 5xx errors create a poor user experience and can signal neglect to search engines.
Content Checklist
- No thin pages (under 300 words with no other value) — Pages with minimal content that do not serve a clear user intent drag down your site's overall quality signal. Either expand them with useful content or consolidate them into a more comprehensive page.
- Duplicate and near-duplicate page groups are resolved — Cluster similar pages with crawl hashes and content comparison, then inspect purpose, canonical signals and search demand. Consolidate, canonicalise or differentiate only after deciding which URLs users need.
- Content matches the user's search task — Compare the page with relevant queries and current results, then check whether it supplies the expected answer, evidence and next step. Treat result formats as evidence, not a rule that one format can never rank.
- E-E-A-T signals are present on important pages — Author bios, credentials, editorial policies, source citations, and publication dates build Experience, Expertise, Authoritativeness, and Trustworthiness. Critical for YMYL content.
- Content is up to date — Pages referencing outdated statistics, discontinued products, or past events signal neglect. Review your most important pages and update anything that has become stale.
- No keyword stuffing or over-optimisation — Unnatural keyword repetition can trigger spam filters. If the content reads awkwardly because of forced keyword placement, rewrite it naturally.
- Above-the-fold content is useful (not just ads or CTAs) — Pages that push the main content below the fold in favour of ads or interstitials violate page experience guidelines.
- Content covers the necessary decisions — Identify missing questions from user research, search data, first-party expertise and authoritative sources. Add material that belongs on this page and link to separate tasks.
- No auto-generated content published without human review — Google penalises unhelpful content regardless of how it was produced. Every published page should be reviewed by a subject-matter expert.
- Blog posts link to relevant pillar pages — Supporting content should link to and reinforce your main topic pages, building topical authority through a hub-and-spoke internal linking model.
UX and Design Checklist
- Site is fully responsive across mobile, tablet, and desktop — Test on physical devices, not just browser resizing. Emulators miss touch-target issues, font rendering differences, and viewport-specific layout bugs.
- Navigation is intuitive with a clear hierarchy — Users should be able to find any major section within two clicks from the homepage. Menu labels should be descriptive and standard.
- Touch targets meet size or spacing needs — Test WCAG 2.2 AA's 24 by 24 CSS pixel criterion and its exceptions. Consider larger controls for frequent or high-risk actions.
- Forms are easy to complete on mobile — Input fields should use the correct input type (email, tel, number) to trigger the appropriate mobile keyboard. Labels should be persistent, not placeholder-only.
- 404 page is helpful with navigation options — A custom 404 page with a search box, links to popular pages, and a friendly message recovers users who land on broken URLs instead of bouncing them.
- No intrusive interstitials or pop-ups on mobile — Page experience guidelines penalise mobile interstitials that cover the main content. Cookie consent banners are exempt; marketing pop-ups are not.
- Text remains readable and resizable — Test representative text at browser zoom and narrow widths for clipping, overlap and loss of function. Choose size, line height and measure from the typeface and context rather than a single pixel minimum.
- Color contrast meets WCAG AA standards (4.5:1 for text) — Insufficient contrast makes text hard to read for users with visual impairments. Test with the WAVE accessibility checker.
- Breadcrumb navigation is present and functional — Breadcrumbs help users understand their location within the site hierarchy and generate breadcrumb rich results when marked up with schema.
- Call-to-action buttons are clear and consistent — Every page should have a clear next step. CTAs should stand out visually, use action-oriented language, and be consistent in style across the site.
Security Checklist
- HSTS is evaluated before rollout — Confirm HTTPS on required hosts and subdomains, then choose duration, subdomain scope and preload through security change control.
- Content-Security-Policy header is configured — CSP prevents cross-site scripting attacks by restricting which resources can be loaded. Start with a report-only policy and tighten it over time.
- X-Content-Type-Options is set to nosniff — Prevents browsers from MIME-sniffing responses away from the declared content type, blocking a common attack vector.
- X-Frame-Options is set to DENY or SAMEORIGIN — Prevents your pages from being embedded in iframes on other sites, protecting against clickjacking attacks.
- No sensitive files are publicly accessible — Check for exposed .env files, wp-config.php backups, .git directories, database dumps, and phpinfo pages.
- CMS and plugins are updated to latest versions — Outdated WordPress cores, plugins, and themes are the primary attack vector for website compromises. Check for updates at least monthly.
- Admin login pages are not at default URLs — Default login paths like /wp-admin are targeted by brute-force bots. Use a security plugin to change the login URL and implement rate limiting.
- No Google Safe Browsing warnings — Check your site in the Transparency Report. A warning flag devastates traffic and trust. If flagged, clean the malware and request a review immediately.
- Backup system is in place and tested — Verify isolated copies, job alerts, retention and a documented restore against recovery objectives. Set the restore-test cadence from service risk and change frequency.
- Permissions-Policy header restricts unnecessary browser APIs — Limit access to camera, microphone, geolocation, and other browser features your site does not need.
Performance Checklist
- Largest Contentful Paint (LCP) within 2.5 seconds — Check the 75th-percentile field value and trace the responsible element and LCP subparts.
- Interaction to Next Paint (INP) at most 200 milliseconds — Trace affected interactions to separate input delay, event processing and presentation delay.
- Cumulative Layout Shift (CLS) at most 0.1 — Inspect shift clusters and the responsible images, fonts, embeds or injected content before choosing a fix.
- Images are optimised (WebP/AVIF, responsive srcset) — Images are typically the largest payload on any page. Convert to modern formats, implement responsive images, and lazy-load below-fold images.
- CSS and JavaScript are minified — Remove unnecessary whitespace, comments, and dead code from production assets. Most build tools handle this automatically.
- Non-critical CSS and JS are deferred — Render-blocking resources delay the initial paint. Inline critical CSS for above-fold content, defer everything else, and load third-party scripts with async or defer.
- Browser caching is configured with appropriate max-age — Static assets should have Cache-Control headers with max-age of at least one year. Use content hashing in filenames for cache busting.
- Edge delivery is evaluated where useful — Measure latency, cache status, hit ratio and origin load by location. Use a CDN when the audience and workload justify it, then verify actual improvement.
- Text responses use suitable content encoding — Check Brotli or gzip negotiation and transferred bytes for HTML, CSS, JavaScript and other compressible responses.
- No unnecessary third-party scripts — Every third-party script adds latency and main thread blocking. Audit every script for necessity and defer or remove the ones that do not justify their performance cost.
Download the Checklist
The printable PDF is a separate 50-check resource. Use the blank Markdown files in the toolkit to track evidence, status, priorities and owners for this 66-check guide.
For blank Markdown files that help you collect evidence, prioritise findings and assign implementation work, use the agency audit toolkit. It is a separate working resource from this 66-check guide and the printable 50-check PDF.
For the manual checklist page and its scoring notes, see our audit checklist template.
If you are auditing an online store, our ecommerce audit checklist adds 20+ additional checkpoints specific to product pages, category structures, checkout flows, and ecommerce schema.
For WordPress sites, our WordPress audit checklist covers plugin auditing, theme performance, database optimisation, and CMS-specific security checks.
Prefer to have an expert run through this checklist for you? Our professional audit service can use the relevant checks to build a prioritised action plan starting at $297.
Check Your Page HTML
Review titles, canonical links and other on-page signals from pasted HTML. Download your findings for follow-up.
Open HTML CheckerNo signup required • Pasted HTML stays in your browser
Continue Reading
SEO Audit Checklist
Detailed SEO-specific audit checklist.
Audit Template
Free 50-check PDF template for a manual website audit.
Ecommerce Audit Checklist
Audit checklist tailored for online stores.
WordPress Audit Checklist
WordPress-specific audit checklist.
Content Audit Template
Spreadsheet columns, scoring system, and action categories for content audits.
Security Audit Checklist
SSL, headers, authentication, and backups covered in one practical checklist.
Accessibility Audit Checklist
WCAG-aligned checkpoints for colour contrast, keyboard navigation, and screen readers.
Website Redesign Audit Checklist
What to check before and after a redesign so you don't lose rankings or traffic.