Checklist Updated September 2026 12 min read

The 47-Point Website Audit Checklist for Agencies & Developers (2026 Edition)

A comprehensive, field-tested 47-point checklist spanning Technical SEO, Core Web Vitals, SSL security headers, mobile usability, and conversion architecture.

Short on time? Automate this entire checklist with LeadForge.
Run Automated Audit →

1. Technical SEO & Crawlability (Points 1–12)

Ensure search engines can discover, crawl, and interpret your website content without friction or crawl budget waste.

  • 1. Robots.txt Validity: Verify that robots.txt exists, does not block critical CSS/JS assets, and specifies the XML sitemap URL.
  • 2. XML Sitemap Hygiene: Validate that the sitemap is accessible, returns HTTP 200, uses HTTPS URLs, and excludes noindexed or redirected pages.
  • 3. Canonical Tag Configuration: Verify every indexable page contains an absolute self-referencing canonical tag.
  • 4. Meta Robots Directives: Ensure money pages are set to index, follow and private admin/onboarding pages are strictly noindex.
  • 5. HTTP Status Codes: Confirm primary URLs return HTTP 200 OK without unneeded intermediate 301/302 redirects.
  • 6. Redirect Chains: Eliminate multi-hop redirect chains (e.g., HTTP → HTTPS → www → non-www).
  • 7. 404 Error Handling: Ensure broken URLs return a genuine HTTP 404 status rather than soft-404 200 responses.
  • 8. Title Tag Optimization: Unique titles under 60 characters with primary keywords placed early.
  • 9. Meta Description Optimization: Compelling summaries between 120 and 160 characters.
  • 10. Single H1 Tag: Ensure exactly one semantic <h1> per page summarizing primary topic intent.
  • 11. Heading Structure (H2–H6): Logical nesting hierarchy without skipped levels.
  • 12. Schema.org JSON-LD: Valid structured data for Organization, WebSite, and page-specific entities.

2. Performance & Core Web Vitals (Points 13–24)

Fast page speeds drive organic ranking boosts and higher user engagement.

  • 13. Time to First Byte (TTFB): Server response under 600ms on broadband and 1.2s on mobile.
  • 14. Largest Contentful Paint (LCP): Primary content renders in under 2.5 seconds.
  • 15. Cumulative Layout Shift (CLS): Visual stability score below 0.1.
  • 16. Text Compression: Brotli or Gzip enabled for HTML, CSS, JavaScript, and SVG files.
  • 17. Next-Gen Image Formats: Serve images in modern WebP or AVIF formats.
  • 18. Explicit Image Dimensions: Width and height attributes set on <img> elements to prevent layout shifts.
  • 19. Render-Blocking CSS: Inline critical CSS and load secondary stylesheets asynchronously.
  • 20. Script Deferral: Non-critical JavaScript marked with defer or async.
  • 21. Browser Caching: Cache-Control headers set with long max-age for static media and fonts.
  • 22. Font Display Optimization: Use font-display: swap to eliminate invisible text delay.
  • 23. HTTP/2 or HTTP/3 Protocol: Modern multiplexed transport protocols enabled on the server.
  • 24. Total Page Payload: Total page transfer weight kept under 2MB for standard pages.

3. Security & Infrastructure Hygiene (Points 25–34)

Transport encryption and security headers defend users and prevent browser warning badges.

  • 25. HTTPS Enforcement: Automatic 301 redirection from HTTP to HTTPS across all URLs.
  • 26. TLS Certificate Validity: Valid certificate with at least 30 days before expiration.
  • 27. HSTS Header: Strict-Transport-Security with max-age=31536000.
  • 28. X-Frame-Options: Protection against clickjacking via SAMEORIGIN or DENY.
  • 29. X-Content-Type-Options: Prevent MIME-sniffing with nosniff.
  • 30. Referrer-Policy: Set to strict-origin-when-cross-origin.
  • 31. Permissions-Policy: Explicitly restrict camera, microphone, and geolocation access.
  • 32. No Mixed Content: Zero passive or active HTTP resources loaded on HTTPS pages.
  • 33. Software Version Masking: Hide server banner tokens (e.g., Apache, Nginx, PHP versions).
  • 34. SSRF Defense: Outbound webhook handlers must validate external endpoints against RFC 1918 private ranges.

4. Mobile Usability & UX (Points 35–41)

  • 35. Viewport Meta Tag: Valid width=device-width, initial-scale=1.0 tag.
  • 36. Touch Target Spacing: Buttons and links have minimum 48x48px hit areas with adequate padding.
  • 37. Legible Font Sizes: Body text minimum 16px to prevent pinch-zooming on mobile devices.
  • 38. No Horizontal Scrolling: Fluid layouts that fit viewport boundaries without overflow.
  • 39. Mobile Navigation Accessibility: Hamburger menus are keyboard operable and aria-expanded compliant.
  • 40. Form Input Types: Explicit input types (email, tel, number) for appropriate mobile keyboards.
  • 41. Tap Delay Elimination: Fast response without legacy 300ms mobile touch delays.

5. Conversion & Agency Presentation (Points 42–47)

  • 42. Clear Value Proposition: Hero section clearly states who the product serves and what problem it solves.
  • 43. Prominent Call-to-Action: Primary CTA button visually distinguished above the fold.
  • 44. Trust Proof & Social Signals: Badges, certifications, client logos, and compliance statements.
  • 45. Working Lead Capture: Contact forms and checkout funnels test positive with zero JS console errors.
  • 46. Branded PDF Deliverable: Technical audit findings packaged into an executive-ready proposal.
  • 47. Commercial Proposal Integration: Scopes of work linked directly to instant online invoice payments.

Frequently Asked Questions

We recommend performing a baseline technical audit quarterly, with automated monthly health scans to catch broken links, slow third-party scripts, and canonical errors before they impact revenue.

Yes. This 47-point checklist is structured specifically for digital agency discovery phases and technical intake reviews.

Automate All 47 Points in 30 Seconds

Stop auditing manually. Let LeadForge scan any website and produce instant client-ready deliverables.