Skip to main content
Blog
SEOAEO / GEO15 min readBy Samuel Wang

How to Do an SEO Audit in 2026: The 82-Point Checklist We Run on Every Site

How to do an SEO audit, step by step. The 82-point checklist we run on every client site, from indexing to AI search, and what to fix first.

seo auditseo audit checklistwebsite audittechnical seoai search

Quick Answer

An SEO audit is a check of everything that decides whether your site gets found: indexing, speed, structure, content, and proof. We have run 27 of them for real businesses so far. This guide shares the full 82-point checklist we use, in the order we check it, and what to fix first.

  • Start with indexing. If Google has not indexed the page, nothing else on this list matters yet.
  • The score is not the point. An audit is awareness. The value is in what you fix afterwards.
  • Five areas. Technical health, indexing, on-page structure, content, and proof.
  • AI search is part of it now. ChatGPT and Perplexity read your site too, and they read it differently.
  • Ours is free. Ask us and we run the first pass on your site, no charge.

What an SEO audit is, and the part most people skip

An SEO audit is a structured look at your website through the eyes of a search engine. It checks whether your pages can be found, read, understood, and trusted. The output is a list of findings, usually ranked by how much each one hurts.

Here is the part most people skip. The audit itself changes nothing.

An audit is awareness. It tells you what is going on, and without one you genuinely do not know. But we have seen businesses hold a paid audit for months without acting on a single finding. The site stayed exactly where it was.

So treat the audit as step one of a fix list, not as a report to file away. The score matters less than the top three items on it. If you only have time for those three, that is still a better outcome than reading all 82 findings and doing nothing.

Where we start: is the site indexed at all?

The first thing we check on any new site is indexing. Are the pages in Google's index or not?

It sounds too basic to be step one. It keeps being the finding that matters most. A page that is not indexed cannot rank, cannot be cited, and cannot bring a single visitor, no matter how good the content is. Everything else in an audit assumes this step passed.

Two quick ways to check your own site right now:

  1. Search Google for site:yourdomain.com. If key pages are missing, you have an indexing problem.
  2. In Google Search Console, paste a URL into the inspection bar. It tells you whether the page is indexed, and if not, why.

If pages are missing, the audit becomes a hunt for the reason. A stray noindex tag, a robots.txt block, a page Google discovered but never crawled, or a site so new it has no signals yet. We have hit all of these on real client sites, including our own.

The tools we use

We keep the toolset small. Most of an audit is looking at the site itself, raw.

  • Google Search Console. Indexing status, real queries, real clicks. Free, and the closest thing to Google telling you directly.
  • Google PageSpeed Insights. Speed and Core Web Vitals, on real-user data where it exists.
  • Ahrefs. Keyword positions, competitor comparison, content gaps.
  • Ubersuggest. A second read on keywords and site health.
  • Claude. We built our audit checks as AI skills, and Claude runs the repetitive passes: fetching pages, reading raw HTML, flagging what fails. The judgment stays ours. We are open about this because it is why our audits are fast and consistent.

One honest note: no tool on this list does the thinking. Every tool outputs findings. Deciding which finding is costing you money, and what to do about it, is the actual work.

How we run it

The process behind every audit we deliver is the same five passes.

  1. Fetch the pages raw. Homepage, key pages, and the 404 page, as plain HTML with JavaScript off. We save the evidence so every finding has proof behind it.
  2. Check the root files. robots.txt, sitemap.xml, llms.txt. What crawlers are allowed in, and what they are told about the site.
  3. Inspect every key page. Titles, descriptions, headings, canonical tags, structured data, social tags. The full on-page pass.
  4. Read the content the way an engine would. Can a machine lift a clear answer from this page? Is there anything specific enough to quote? This is where most sites lose.
  5. Check the outside view. What Search Console says, what competitors rank for, and what ChatGPT and Perplexity currently say about the brand.

Then we rank the findings by severity and cost. Cheap and visible fixes first. A missing meta description takes minutes. A rebuild is a project. They do not belong on the same line of the to-do list.

The 82-point checklist

This is the full list. It comes from 611 individual findings across the 27 audits we have delivered, deduplicated into the checks we now run every time. Nothing held back. You can run every item yourself, or ask us to run the first pass and start from its findings.

Technical health (12 checks)

  • Site is online and reachable. No intermittent errors, no expired domain surprises.
  • HTTPS is forced. The http:// version redirects to https:// in one hop.
  • Server responds fast. Slow first response drags every other metric down.
  • No redirect chains. One redirect is fine. Three in a row wastes crawl and speed.
  • Page weight is sane. Multi-megabyte pages lose visitors on mobile connections.
  • Mobile viewport is set. Without it, phones render the desktop page shrunken.
  • Core Web Vitals pass. LCP, INP, and CLS in the green on real-user data.
  • Content is server-rendered. Turn JavaScript off. If the page goes blank, most AI crawlers see the blank version.
  • The platform is current and supported. Abandoned builders and ancient plugins show.
  • No injected spam. Hacked sites carry hidden pages and links the owner never sees.
  • Analytics is installed and firing. You cannot improve what you do not measure.
  • Search Console is connected. Free data, direct from Google. No excuse to skip it.

Indexing and crawl (12 checks)

  • Key pages are actually in Google's index. The site: check. Step one, always.
  • No accidental noindex tags. A leftover staging tag can hide a whole site.
  • robots.txt exists and is not blocking what matters. We have seen entire sites disallowed by mistake.
  • AI crawlers are explicitly allowed. GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended. If they are blocked, AI engines cannot read you.
  • The XML sitemap is valid. Real URLs, no errors, no dead entries.
  • Sitemap dates are honest. lastmod values that never change tell engines the site is stale.
  • robots.txt points to the sitemap. One line. Often missing.
  • The 404 page works. Dead URLs return a real 404, not a soft error page that gets indexed.
  • No thin or test pages in the index. Demo pages, placeholder pages, tag archives with one post.
  • No duplicate pages competing. Two URLs with the same content split their strength.
  • llms.txt exists. A small file that tells AI engines what the site is. Cheap to add, low priority, still worth having.
  • No broken internal links. Every dead link wastes a click and a crawl.

On-page structure (15 checks)

  • Every page has a title tag. Empty titles still happen more than you would think.
  • Titles are unique. Ten pages titled "Home" compete with each other.
  • Titles are descriptive. What the page is, plus where, for local businesses.
  • The brand is spelled correctly in titles. We found a client's own name typoed in their homepage title.
  • Every page has a meta description. Google writes its own when you do not, and Google is not your copywriter.
  • Descriptions are written for humans. The description is your ad in the results page.
  • One H1 per page. One clear statement of what the page is about.
  • Headings are in logical order. H2 under H1, H3 under H2. Engines read the outline.
  • No typos in headings. Headings get quoted. Typos get quoted with them.
  • Canonical tags are set and correct. Each page names its one true URL.
  • The lang attribute matches the content. An English site declaring itself something else confuses engines.
  • Open Graph tags are complete. Title, description, image, and URL for link previews.
  • Twitter card tags are present. The same preview, for the platforms that use them.
  • The social preview image is real. A branded image, not a random theme asset or nothing.
  • No obsolete or duplicate head directives. Old meta keywords tags, doubled-up directives, leftovers from past plugins.

Content and citability (12 checks)

  • Core pages have real depth. A service page with two sentences cannot answer anything.
  • Answer blocks stand on their own. A paragraph that fully answers one question, readable with nothing around it. This is what AI engines actually quote.
  • There is a buyer FAQ. The questions real customers ask, answered in plain words.
  • The FAQ carries FAQPage schema. Marked up so engines know question from answer.
  • Service descriptions are liftable prose. Full sentences a machine can quote, not fragments in a design grid.
  • Specific facts are stated plainly. Prices, numbers, years, place names. Specifics get cited. Vague claims get skipped.
  • Pricing is transparent where possible. "From S$X" beats "contact us for a quote" in both search and trust.
  • Services and methods have names. A named process is quotable. "Our proven approach" is not.
  • Dates are visible and content is fresh. An engine can tell when a site went quiet.
  • There is editorial activity. A blog or guides section that shows the business is alive.
  • One page per topic. Two pages chasing the same keyword split the vote. This is keyword cannibalization, and we check for it on every audit.
  • No duplicated content across pages. Copy-pasted service pages with one word swapped count as duplicates.

Structured data (8 checks)

  • Organization or LocalBusiness schema exists. The machine-readable statement of who you are.
  • Schema carries the full identity. Name, address, phone, and logo, complete and current.
  • One consistent business entity. Not two names, two addresses, or a legal name that fights the brand name.
  • Service or Product schema on offer pages. Label what you sell.
  • BreadcrumbList is present. Cheap markup that clarifies site structure.
  • Reviews are machine-readable. Real testimonials marked up as reviews with an aggregate rating.
  • Review counts are consistent. The number in the schema matches the number on the page.
  • The whole graph validates. Run it through the Rich Results Test. Broken schema is worse than none.

Authority and proof (10 checks)

  • NAP is consistent everywhere. Same name, address, and phone on the site, Google Business Profile, and directories. Engines cross-check.
  • Registered-business credentials are stated. UEN, licences, certifications, years in operation. Real signals, stated in plain text.
  • sameAs links point to real profiles. Schema that connects the site to its social and directory presence.
  • A LinkedIn company page exists. The baseline entity signal for a real business.
  • Industry directory listings exist. The places engines look to confirm you are real.
  • A knowledge-graph entity where realistic. Wikidata for established brands. Not worth forcing for a new one.
  • Named client proof. Case studies with real names beat logo walls with no story.
  • Testimonials are real and attributable. A name and a company. Anonymous praise reads as invented, to people and machines alike.
  • Press and media mentions are surfaced. If you were covered, say so, and link it.
  • The about page tells the entity story. Who is behind this, since when, and why they can be trusted.

Media (7 checks)

  • Key pages have images. All-text pages read as thin to modern engines.
  • Alt text describes the image. For accessibility first, and for the engines that read it. Not a keyword dump.
  • Media has captions and context. An image with a caption is worth more than ten without.
  • Image schema where it earns it. Product shots and key visuals, labeled.
  • Photography is original. Engines have seen every stock photo. So have your visitors.
  • Text in images also exists as text. Client logos and infographic claims are invisible if they only live in pixels.
  • Video is transcribed or structured. A video with no transcript is content only humans can use.

The outside view (6 checks)

  • Organic traffic trend. Up, flat, or down over the last year, and since which date.
  • Real queries and clicks. What Search Console says you actually show up for, versus what you think.
  • Pages losing position. Rankings that decay quietly are the earliest warning sign.
  • Competitor comparison. Who wins the keywords you care about, and what their pages do differently.
  • Content gaps. Questions your competitors answer that your site does not.
  • AI search visibility. Ask ChatGPT and Perplexity about your business by name, and about your category without it. What comes back is your current AI presence.

We do not audit backlink profiles, and we would rather say that plainly than pad the checklist.

Two reasons. First, for the small and mid-sized businesses we audit, a toxic-link cleanup is almost never the thing holding them back. The blockers live on the site itself: indexing, structure, and content that says nothing specific. Second, the data has shifted. An Ahrefs study of 75,000 brands found that how often a brand is mentioned across the web tracks AI visibility about three times more closely than backlinks do. We wrote about that in how AI engines choose what to cite.

If you have a genuine link problem, a penalty, or an enterprise profile to manage, Ahrefs does that job well. It is simply not what we sell.

What to do with the findings

Rank them, then fix in cost order. This is the sequence we use on every engagement:

  1. Hygiene first. Titles, descriptions, canonical, robots, sitemap, schema, analytics. Hours of work, visible within weeks.
  2. Content second. Rewrite key pages into answer blocks and a real FAQ. Days of work, and where the citability comes from.
  3. Rebuild last, if at all. Only once the first two phases prove there is demand worth building for.

The order matters because momentum matters. A business that ships ten small fixes in week one keeps going. A business handed a rebuild quote on day one usually does nothing.

The &7 take

We are a web studio in Singapore, and our first-pass audit is free. Send us your URL and we run it: a score and the top gaps, no charge. The full checklist above is public because the list was never the secret.

Here is the honest version of why. Anyone can run an audit. The tools are listed on this page and most of them are free. What businesses actually pay for is what comes after: someone who explains which findings matter, makes the changes, and measures whether they worked. That consultation and implementation is our SEO, AEO and GEO service. The audit is just the map.

We also hold ourselves to the same list. When we audited our own studio, the pages we had ranked in Google were not the ones AI engines named, and that finding reshaped how we write every page on this site.

Ask us for the free first pass. If the findings look like work you want handled, we take it from there. If you would rather fix them yourself, this page is everything we would check.

Frequently asked questions

Why is an SEO audit important?

Because without one you are guessing. An audit replaces "the site feels slow" and "we should rank better" with a ranked list of specific findings: this page is not indexed, this title is empty, this service page has nothing an engine can quote. You cannot prioritize fixes you have not found. One audit usually pays for its time with the first critical finding alone.

What is included in an SEO audit?

A complete audit covers five areas. Technical health: speed, HTTPS, mobile, rendering. Indexing: whether your pages are in Google at all, and whether crawlers including AI bots can reach them. On-page structure: titles, descriptions, headings, schema. Content: whether pages answer real questions with real specifics. And proof: whether the wider web confirms your business is real and trusted. The 82 checks above cover all five.

How long does an SEO audit take?

The automated first pass is fast, and we run it for you free: send us your URL to start there. A full manual audit of a small site takes us under a day, because Claude runs the repetitive checks and we spend our time on the judgment calls. Without AI assistance, plan for several days on a site of any real size. Large sites with hundreds of pages take longer at any level of tooling.

How often should you do an SEO audit?

Do a full audit once a year, and a short re-check after any significant change: a redesign, a platform move, a batch of new pages, or a sudden traffic drop. The re-check matters more than the calendar. Most SEO damage we see was caused by a site change nobody audited afterwards, and it sat unnoticed for months.

How much does an SEO audit cost in Singapore?

Agencies in Singapore sell audits at anywhere from a few hundred to a few thousand dollars, usually scaled by site size. Ours is free, including the full report. We price the work that follows instead: explaining the findings, making the fixes, and measuring the results. Paying for the map only makes sense if it comes with someone willing to drive.

About the author

Samuel Wang

Founder, &7

Samuel Wang is the founder of &7, an interactive and immersive web studio in Singapore. He writes about growing the studio in public: SEO and GEO, automation, conversion, and what actually moves the needle for a small business.

I write these guides from running the studio and doing the work, not from a keyword tool. Where I have real numbers I show them. Where I don't yet, I say so.

More in SEO