Checklist
Updated September 2026
12 min read
The 47-Point Website Audit Checklist for Agencies & Developers (2026 Edition)
A comprehensive, field-tested 47-point checklist spanning Technical SEO, Core Web Vitals, SSL security headers, mobile usability, and conversion architecture.
Short on time? Automate this entire checklist with LeadForge.
Run Automated Audit →
1. Technical SEO & Crawlability (Points 1–12)
Ensure search engines can discover, crawl, and interpret your website content without friction or crawl budget waste.
- 1. Robots.txt Validity: Verify that robots.txt exists, does not block critical CSS/JS assets, and specifies the XML sitemap URL.
- 2. XML Sitemap Hygiene: Validate that the sitemap is accessible, returns HTTP 200, uses HTTPS URLs, and excludes noindexed or redirected pages.
- 3. Canonical Tag Configuration: Verify every indexable page contains an absolute self-referencing canonical tag.
- 4. Meta Robots Directives: Ensure money pages are set to
index, followand private admin/onboarding pages are strictlynoindex. - 5. HTTP Status Codes: Confirm primary URLs return HTTP 200 OK without unneeded intermediate 301/302 redirects.
- 6. Redirect Chains: Eliminate multi-hop redirect chains (e.g., HTTP → HTTPS → www → non-www).
- 7. 404 Error Handling: Ensure broken URLs return a genuine HTTP 404 status rather than soft-404 200 responses.
- 8. Title Tag Optimization: Unique titles under 60 characters with primary keywords placed early.
- 9. Meta Description Optimization: Compelling summaries between 120 and 160 characters.
- 10. Single H1 Tag: Ensure exactly one semantic <h1> per page summarizing primary topic intent.
- 11. Heading Structure (H2–H6): Logical nesting hierarchy without skipped levels.
- 12. Schema.org JSON-LD: Valid structured data for Organization, WebSite, and page-specific entities.
2. Performance & Core Web Vitals (Points 13–24)
Fast page speeds drive organic ranking boosts and higher user engagement.
- 13. Time to First Byte (TTFB): Server response under 600ms on broadband and 1.2s on mobile.
- 14. Largest Contentful Paint (LCP): Primary content renders in under 2.5 seconds.
- 15. Cumulative Layout Shift (CLS): Visual stability score below 0.1.
- 16. Text Compression: Brotli or Gzip enabled for HTML, CSS, JavaScript, and SVG files.
- 17. Next-Gen Image Formats: Serve images in modern WebP or AVIF formats.
- 18. Explicit Image Dimensions: Width and height attributes set on <img> elements to prevent layout shifts.
- 19. Render-Blocking CSS: Inline critical CSS and load secondary stylesheets asynchronously.
- 20. Script Deferral: Non-critical JavaScript marked with
deferorasync. - 21. Browser Caching: Cache-Control headers set with long max-age for static media and fonts.
- 22. Font Display Optimization: Use
font-display: swapto eliminate invisible text delay. - 23. HTTP/2 or HTTP/3 Protocol: Modern multiplexed transport protocols enabled on the server.
- 24. Total Page Payload: Total page transfer weight kept under 2MB for standard pages.
3. Security & Infrastructure Hygiene (Points 25–34)
Transport encryption and security headers defend users and prevent browser warning badges.
- 25. HTTPS Enforcement: Automatic 301 redirection from HTTP to HTTPS across all URLs.
- 26. TLS Certificate Validity: Valid certificate with at least 30 days before expiration.
- 27. HSTS Header:
Strict-Transport-Securitywithmax-age=31536000. - 28. X-Frame-Options: Protection against clickjacking via
SAMEORIGINorDENY. - 29. X-Content-Type-Options: Prevent MIME-sniffing with
nosniff. - 30. Referrer-Policy: Set to
strict-origin-when-cross-origin. - 31. Permissions-Policy: Explicitly restrict camera, microphone, and geolocation access.
- 32. No Mixed Content: Zero passive or active HTTP resources loaded on HTTPS pages.
- 33. Software Version Masking: Hide server banner tokens (e.g., Apache, Nginx, PHP versions).
- 34. SSRF Defense: Outbound webhook handlers must validate external endpoints against RFC 1918 private ranges.
4. Mobile Usability & UX (Points 35–41)
- 35. Viewport Meta Tag: Valid
width=device-width, initial-scale=1.0tag. - 36. Touch Target Spacing: Buttons and links have minimum 48x48px hit areas with adequate padding.
- 37. Legible Font Sizes: Body text minimum 16px to prevent pinch-zooming on mobile devices.
- 38. No Horizontal Scrolling: Fluid layouts that fit viewport boundaries without overflow.
- 39. Mobile Navigation Accessibility: Hamburger menus are keyboard operable and aria-expanded compliant.
- 40. Form Input Types: Explicit input types (email, tel, number) for appropriate mobile keyboards.
- 41. Tap Delay Elimination: Fast response without legacy 300ms mobile touch delays.
5. Conversion & Agency Presentation (Points 42–47)
- 42. Clear Value Proposition: Hero section clearly states who the product serves and what problem it solves.
- 43. Prominent Call-to-Action: Primary CTA button visually distinguished above the fold.
- 44. Trust Proof & Social Signals: Badges, certifications, client logos, and compliance statements.
- 45. Working Lead Capture: Contact forms and checkout funnels test positive with zero JS console errors.
- 46. Branded PDF Deliverable: Technical audit findings packaged into an executive-ready proposal.
- 47. Commercial Proposal Integration: Scopes of work linked directly to instant online invoice payments.
Frequently Asked Questions
We recommend performing a baseline technical audit quarterly, with automated monthly health scans to catch broken links, slow third-party scripts, and canonical errors before they impact revenue.
Yes. This 47-point checklist is structured specifically for digital agency discovery phases and technical intake reviews.