Full capability list
What works today, and what does not
Most audit tools publish a feature list. This is the same list with the truth attached: which checks are live, which are live with a stated limit, and which are still on the roadmap. Your audit deck carries the same table, so a quiet section never reads as a clean one.
Snapshot
100%
of this tier is live today
- Live
- 45
- Live, with a limit
- 13
- On the roadmap
- 0
- Total in scope
- 58
Professional
98%
of this tier is live today
- Live
- 71
- Live, with a limit
- 15
- On the roadmap
- 2
- Total in scope
- 88
Enterprise
92%
of this tier is live today
- Live
- 74
- Live, with a limit
- 15
- On the roadmap
- 8
- Total in scope
- 97
How to read this. A capability marked live has been run against real websites and appears in the deck. Live with a limit means it works and the deck states plainly what it cannot see. Placeholder means we sell it but have not built it, and we will tell you before you buy. Nothing on the roadmap is implied anywhere in a deck.
AI visibility & answer readiness
| Capability | Status | Tier | Source |
|---|---|---|---|
AI crawler access for 17 named agents Deeper than any of the five reference decks. | Live | snapshot | robots.txt fetch |
llms.txt and llms-full.txt presence | Live | snapshot | own fetch |
llms.txt curation quality: entry count, description coverage, generator | Live | snapshot | own fetch |
Answer readiness: answer-first openings, question headings, FAQ blocks, tables, freshness | Live | snapshot | crawl HTML |
Passage chunking and table-of-contents depth | Live | snapshot | crawl HTML |
JavaScript-dependency verdict Measured by comparing the blocks of text a visitor reads against the body of the response the browser itself navigated to, so both halves come from one request. Reported as not measured, never as a pass or a failure, when the page carries too little text to compare or when the only available copy of the served HTML was cut at the crawler's size cap. At Professional it is measured on every page in the render sample and reported over the pages the comparison could be made on. Where the browser measured nothing, the deck falls back to a text-to-script ratio read from the page source and says which of the two produced the verdict. | Live | snapshot | rendered DOM diffed against the served HTML |
Live AI visibility: mention, citation and recommendation rates across answer engines Measures DataForSEO's stored corpus of 316 million AI answers across 94 markets, which is a large sample of what answer engines say and not a census, so figures will not reconcile with anyone's analytics. Coverage is lopsided: ChatGPT exists for the United States in English only, everywhere else the corpus is Google AI Overviews alone, and there is no Perplexity, Claude, Copilot or Gemini data at all. Breakdowns cap at ten keys, so market and rival tables are tops rather than totals and the module prints how much of the total they cover. For a one-word brand the name-match figure is a ceiling and only the subset that also cites the site is a floor; nothing between the two can be classified. | Live | professional | live engine queries, logged verbatim with timestamps |
AI share of voice against named competitors, prompt by prompt Compares how often each named competitor is used as a source in a stored AI answer, in one call covering the whole field. It is a share of citations, not of recommendations: nothing here says an engine preferred one company, only that it drew on their site. A peer cited more than twenty times the field's median is excluded from the percentages and named, because a general-purpose giant that happens to share keywords renders every real competitor as zero: measured together, google.com returned 18,284,295 citations against plausible.io's 870. The comparison is only as good as the competitor set feeding it. | Live | enterprise | the same battery, scored per competitor |
AI Overview and SERP-feature presence across 30-50 ranking keywords Samples up to fifteen of the keywords the site already ranks for, so it answers whether Overviews appear where the site competes, not across a category. An AI Overview is assembled per search and varies by user, location and moment: two identical runs minutes apart returned different counts, so this is a photograph rather than a measurement and the deck says so. Google only. | Live | professional | DataForSEO SERP, ai_overview item type |
Off-site citation sources: which domains the engines cite for this category These are the domains appearing in the same answers that already cite the client, which is co-citation and not a leaderboard for their category. The API has no reliable way to ask which sites get named when someone asks about a sector: the only scoping mechanism is a loose word match, and asking it about web analytics returned Amazon Web Services and Microsoft Azure. The deck says which of the two this is. | Live | enterprise | cited-domain list from the battery |
AI citation coverage ratio: pages cited over pages crawled Computed over the overlap between pages we crawled and pages answer engines cite, never by dividing the two totals: those are different populations and the quotient exceeded 100% on the first real site tested. The cited list the API returns is capped well below the true total, so the overlap is a floor and is worded as one. The denominator is this audit's crawl rather than the whole site. | Live | enterprise | battery + crawl |
Bing indexation, the index ChatGPT search leans on This cannot tell you how many pages Bing holds, and it cannot tell you a domain is absent from Bing. The site: operator is dead on this endpoint: fourteen request shapes were tested and every one returns no results while still billing. It answers one question only, whether Bing returns this domain when asked about it by name and at what position. A positive is trustworthy; a negative is worthless as evidence, because a genuinely unindexed domain and a scrape served a generic page produce identical responses, so negatives are reported as not measured rather than as absence. | Live | professional | DataForSEO SERP |
Mining a real-time LLM query stream for buyer questions No such public source exists and neither deck showed a sample output. Never claim it. | Deliberately not built | - | claimed by two reference decks |
Per-platform LLM behaviour models Our measured cited-source distribution from the battery is strictly better. | Deliberately not built | - | asserted, untested |
Technical foundation
| Capability | Status | Tier | Source |
|---|---|---|---|
Page crawl: status, titles, descriptions, canonicals, H1s, word count, links 25 pages at Snapshot. Every rate is printed over that stated base. | Live | snapshot | own crawler |
Canonical audit: missing, self-referencing, cross-domain, as a rate | Live | snapshot | existing crawl |
Meta robots directives, including max-snippet and max-image-preview as AEO levers Rated Critical by one reference deck. The absence of max-snippet:-1 anywhere on the site is now its own finding. | Live | snapshot | existing crawl |
External link checking Up to 120 outbound links per audit. Hosts that refuse automated traffic as policy are skipped by name, and anything returning 403, 429, a 5xx or a timeout is reported as unverified rather than counted as broken. | Live | professional | crawl + fetch |
Structured data types found, per page, with sameAs links | Live | snapshot | crawl HTML |
Schema expected-type coverage by page role Roles are classified from the URL path and title, so an unconventional structure lands pages in "other" and they are left out rather than misjudged. | Live | snapshot | page-role classifier + local type map |
Schema property validation against required fields Checks Google's documented required and recommended properties for 20 rich-result types. Types outside that list are listed as not checked rather than passed. It verifies a property is present and populated, not that its value is correct. | Live | professional | Google's rich-result requirements |
Internal link graph: orphans, click depth, inlink counts, editorial to commercial flow Answers within the crawl only. A page linked solely from beyond the 250-page limit would look like an orphan, so when the crawl fills its budget the finding says so and drops in severity. Editorial links are separated from site-wide furniture by how many pages carry the link, not by the markup, so a page both in the footer and cited in prose counts as furniture. | Live | professional | crawl at 250 pages |
URL silo and information-architecture analysis Groups by first path segment, which says nothing about a site that keeps every page at the root. Those are reported as flat rather than scored down for a deliberate choice. | Live | professional | crawl at scale |
Pagination integrity: rel next/prev, sequence errors Detects five common pagination URL patterns; a site paginating another way is not seen. rel=next/prev is reported and not scored, because Google stopped using it as an indexing signal in 2019. A gap in the sequence is treated as the real signal. | Live | professional | crawl at scale |
250-page crawl with 25 rendered pages 250 pages at Professional and Enterprise, with 25 of them rendered in a browser: the render queue is built and both halves of the name are now real. The rendered sample is one page per template chosen for diversity, not the first 25 pages, and pages a protected site refuses are named and excluded rather than counted, so a 25-page sample is routinely a 20-page one and every rate says which. | Live | professional | own infra |
Hreflang structure: clusters, return links, self-reference and x-default conflicts Read from served HTML, response headers and the XML sitemap. Annotations added by JavaScript after load are not seen, so every count is a floor. Return links, self-reference and cluster conflicts are judged only between pages whose own annotation sets were read, and pairs pointing outside that set are reported as not evaluated, never as failures. x-default is excluded from the return-link rate and checked separately, because a fallback is not required to point back at every page that nominated it. On a site showing fewer than two locale signals the whole section is reported as not applicable, which is the correct result for a single-market site and not a fault. | Live | snapshot | the crawl we already did: head markup, response headers and the XML sitemap |
Hreflang value validity, reported as annotations and as distinct values Language codes checked against ISO 639-1, region codes against officially assigned ISO 3166-1 Alpha 2. Script subtags such as Hant are parsed and accepted unchecked. A valid code is not necessarily the right code: nothing verifies that a page tagged de-AT is in German. Counts are reported both as annotations and as distinct values, because one typo templated across 500 sitemap entries is one thing to fix and 500 annotations to change. | Live | snapshot | the same annotation set |
Hreflang alternates checked for status, noindex and canonical Up to thirty alternates per audit are fetched, reusing crawled pages first, taken in declaration order rather than sampled at random. Beyond that they are reported as unchecked, never as passing. noindex and canonical are only read where HTML actually parsed, over a stated smaller base: a target returning a PDF, an image or an error contributes to neither count. Private-range, loopback, link-local and non-http(s) targets are refused and reported as not fetchable. These are ordinary GET requests to URLs the audited site published, and they do not consult the target's robots.txt. | Live | snapshot | direct fetches of URLs the audited site itself published |
Outbound fetch policy for URLs the audited site publishes Checks that follow URLs published by the audited site refuse loopback, RFC 1918, carrier-grade-NAT, link-local and non-http(s) addresses. Literal addresses only: a public hostname resolving to a private address is not caught, which would need DNS resolution plus a pinned-IP connection agent. | Live | snapshot | none |
Scope binding: one registrable domain, subdomain and PDF policy printed A product rule at every tier. Its absence caused a 1,071 / 932 / 305 inconsistency in one reference deck: three different totals for the same site, because sections used different bases. | Live | snapshot | none |
PageSpeed page diagnostics: third-party cost, render-blocking files, unused code on initial load, the LCP element, page weight and composition, first-party versus third-party split, failed requests Everything is one page, loaded once, on a simulated mid-tier phone under lab throttling, so it describes that page and not the site, and it is not what real visitors experienced. Whether a diagnostic appears at all varies between runs of the same page: a second nytimes.com run the same day lost four of the seven blocks to Lighthouse audit errors, and those come through as explicit not-measured states rather than as clean results. Third parties are grouped by registrable domain, so a site serving assets from a second domain has that domain counted as a vendor, and the recognised-vendor totals are a floor because Lighthouse does not know every vendor. Unused JavaScript and CSS are measured during the initial load only: code for other routes or behind an interaction is unused here by design. Render-blocking millisecond figures are the tool simulating this one load, not a measured saving. Failure counts are stated only over the site's own origin, because on six sites measured every HTTP failure belonged to a third party and two were the audit tool itself being rate limited. | Live | snapshot | already inside the PageSpeed response we fetch |
Heading audit: duplicate and multiple H1, H2 structure, non-sequential levels, title-equals-H1 Missing H1, multiple H1s and title-identical-to-H1 are detected. H2 structure and non-sequential heading levels are not yet checked. | Live, with a limit | snapshot | existing crawl |
Title and description length bands with a best-in-class target column Lengths are collected but reported as raw counts, without bands or a target. | Live, with a limit | snapshot | existing crawl |
Status-code distribution, redirect chains and robots-blocked share The status mix across the crawl is counted. Redirect-chain length and the robots-blocked share are not yet measured. | Live, with a limit | snapshot | existing crawl |
Internal broken links as a rate over the crawl base Counted within the 25-page crawl only. External links are not checked at this tier. | Live, with a limit | snapshot | existing crawl |
Sitemap quality: staleness, low-value URLs, duplicates, index structure The URL count reported is the pre-deduplication total seen, which overstates a sitemap that repeats URLs across child sitemaps. Staleness and low-value analysis are not built. | Live, with a limit | snapshot | existing fetch |
1,000-page crawl with 100 rendered pages | On the roadmap | enterprise | own infra |
Experience & performance
| Capability | Status | Tier | Source |
|---|---|---|---|
Core Web Vitals, mobile, field where available and lab otherwise Field data exists only where Chrome has enough traffic for the site; below that threshold the deck reports lab measurement and labels it as such. Read from the CrUX API directly when the Chrome UX Report API is enabled on the key, otherwise from the copy PageSpeed embeds. The same PageSpeed response now also feeds the page diagnostics at no extra call and no extra wait. | Live | snapshot | PageSpeed Insights / CrUX |
Core Web Vitals, desktop, alongside mobile Best effort: the two profiles run at the same time so desktop costs no extra wait, and if the desktop call fails the audit still ships with mobile, which is what Google ranks on. | Live | snapshot | a second PageSpeed call, issued concurrently with the mobile one |
PageSpeed Accessibility, Best Practices and SEO category scores One Lighthouse run on one page from one location, so the scores are directional. On a site slow enough to time out, only the performance category completes and the deck says so. | Live | snapshot | already inside the PageSpeed response we fetch |
Contrast, focus order and keyboard operability on a rendered page Runs axe-core against WCAG 2.1 A and AA on the rendered homepage only. Automated testing covers roughly a third of the WCAG criteria, so a clean result means no machine-detectable failures and is never reported as accessible or compliant. Keyboard traps, focus visibility in practice and whether alt text is accurate still need a person. | Live | professional | headless render + axe-core 4.13 |
Headless render pass: real JS dependency, runtime tags, duplicate analytics IDs, sticky CTA, above-fold geometry A sample of pages chosen one per template, rendered once each, 2.5 seconds after load, with no interaction. Snapshot renders the homepage alone; Professional and Enterprise render 25. A page whose server answers an error status or a bot check is reported as not measured and named, never as a page with nothing on it: allbirds.com served HTTP 429 to 5 of 25 pages on one run and 18 of 25 on an immediate second run. Running the pages runs the site's own analytics, which adds one pageview per rendered page to the client's reporting. | Live | snapshot | Playwright Chromium on own compute |
Client vs server rendered share, against a defined element class Compares headings, paragraphs, links and images separately, so the deck can say which part of the page is missing rather than give one site-wide percentage. Homepage only. An element class the page does not use reports as not applicable rather than as perfectly server-rendered. Items too short to search for reliably are excluded from both sides of the fraction, so a navigation of short link labels is not reported as client-rendered. | Live | professional | rendered DOM diffed against raw HTML |
Navigation option count, clicks to a product page, site search, chat presence Navigation width, site search, chat presence, sticky header, calls to action above the fold and the scroll offset of the first proof point are measured. The taste-level verdict on top of them stays a human add-on. | Live | snapshot | crawl + one render |
Above-fold geometry and the scroll offset of the first proof point Measured at 1280x800 on the homepage, and every finding prints that viewport height alongside the offset, because above the fold means nothing without saying whose fold. Not measured on mobile viewports. | Live | professional | headless render |
Image audit: alt text, dimensions, modern formats, lazy loading Alt text, declared dimensions and lazy loading are read from markup across the crawl. Image format is read from what the server actually sent, because a URL ending .jpg is routinely served as WebP by any CDN that negotiates on Accept, and the filename therefore says nothing about the format: that measurement comes from the homepage network log and the finding is worded as homepage-only. SVG and icon files are excluded from the format comparison rather than counted as legacy. When no network log is available the deck reports what the markup declares and says that is what it is measuring. Total image weight across the site is still not measured. | Live | snapshot | existing crawl |
WCAG static checks: alt text, form labels, heading order, link text, lang, landmarks Collected and scored, but has no slide of its own in the deck yet. Automated testing catches roughly a third of real accessibility issues, so it is a floor rather than a clearance. | Live, with a limit | snapshot | crawl HTML |
Taste-level UX verdicts and competitor UX narrative The measurable substrate ships free; the opinion on top is a human add-on. | Deliberately not built | Add-on | a person |
Conversion & messaging
| Capability | Status | Tier | Source |
|---|---|---|---|
CTA persistence on scroll and same-styled CTA counts Groups calls to action by computed appearance (background, text colour, radius, weight) rather than by class name, because two class names often render identically. Persistence is tested by scrolling to three-quarters depth once; a page that reveals a CTA only on scroll-up is not counted. | Live | professional | headless render |
Open Graph completeness against the four properties the protocol requires, with the rubric printed Scored against the four properties ogp.me states are required and nothing else, over the pages whose HTML parsed. Pages fetched but unreadable are reported separately and are outside the denominator. og:description, og:site_name and twitter:card are counted, not scored. Non-standard og:type is reported as information: the protocol allows vendor-defined types, and every ecommerce site on the web ships og:type=product. og:url is compared with rel=canonical only on pages carrying both, and a page with an og:url and no canonical is counted as not comparable rather than as passing. | Live | snapshot | the crawl we already did |
Value proposition clarity, CTAs per page, forms, contact paths, pricing transparency, social proof Collected and scored, but has no dedicated slide in the deck yet. | Live, with a limit | snapshot | crawl HTML |
Landing-page teardowns for your key pages and competitor pages | On the roadmap | enterprise | render + DeepSeek over measured facts |
Trust, security & brand
| Capability | Status | Tier | Source |
|---|---|---|---|
HTTPS enforcement, TLS protocol, issuer, expiry, security headers graded Deeper than all five reference decks, one of which gave it a single line. | Live | snapshot | TLS handshake + response headers |
Email authentication: SPF with its real lookup cost, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT and MX DKIM selectors cannot be enumerated from DNS: we probe a fixed list of 40 common selectors and print it, and a domain whose sender uses a custom or per-account selector will show no key even though DKIM is working, which is reported as no key at the selectors we probed and never as no DKIM. The SPF lookup count is measured by expanding the record ourselves; where a branch times out or the record uses macros that only expand during a live delivery, the count is a lower bound and the limit verdict is reported as not measured rather than as a pass. Terms written after the all mechanism are reported but not counted, because no receiver reaches them. Everything is read from public DNS, so it describes what the domain publishes and not what it actually sends: only a message's own headers can confirm that. Absence of MX is not reported as accepting no mail, because RFC 5321 has senders fall back to the A record. MTA-STS, TLS-RPT and BIMI are optional and describe the mail channel rather than the website. Every record is read at the registrable domain only, so a client sending from a subdomain shows no key there, and a site sitting directly under a public suffix such as www.gov.uk may have its organisation's records one label up. The registrable domain comes from a short built-in public-suffix list rather than the full IANA list. A resolver returning SERVFAIL is reported as not measured, because it cannot be told apart from a broken DNSSEC signature. Our DKIM sweep and policy fetch are made against the audited domain's own nameservers and web host, so they appear in that domain's DNS and HTTP logs; nothing is written and no form, endpoint or account is touched. | Live | snapshot | public DNS plus at most one HTTPS GET for the MTA-STS policy |
Brand SERP control: what occupies page one for your own name One page, one country, one device, one moment: two calls seconds apart returned different orderings in positions five to seven, so the shape of the page is reliable and the exact ordering is indicative. It cannot identify a competitor. Ownership is certain only for the audited domain and near-certain for known review, directory, social and news hosts; everything else is reported as unclassified and named in full for a human to place. It detects the decisive case where Google substitutes a different word for the query, and it does not detect a brand that is an ordinary word when Google still returns the company. Negative signals are word matches against the headline Google displays, never a reading of the page. | Live | professional | DataForSEO SERP |
Cookie Secure, HttpOnly, SameSite flags and lifetimes Parsed correctly in the consent module, but the old count in the security module used a substring match that mis-flagged cookies. Not yet rendered. | Live, with a limit | snapshot | Set-Cookie headers |
Entity presence: Wikidata, Wikipedia, Google Knowledge Graph, sameAs Knowledge Graph needs GOOGLE_API_KEY. Without it the deck currently renders 'not found' where it should say 'not measured'. | Live, with a limit | snapshot | public APIs |
Review and software-directory presence: Trustpilot, G2, Capterra, TrustRadius Trustpilot only, and it returns 403 to automated requests often enough to be unreliable. The B2B directories are not built. | Live, with a limit | professional | public pages |
Social profile inventory with follower benchmarks Profile links are detected. Follower counts and benchmarks are not. | Live, with a limit | professional | crawl HTML + public profiles |
Cloud marketplace and Product Hunt listings | On the roadmap | professional | public pages |
Measurement & compliance
| Capability | Status | Tier | Source |
|---|---|---|---|
Analytics, tag managers, advertising pixels, CRM and CMS fingerprinting Detects marketing and analytics tools from signatures in the HTML your server returns plus the vendors your own Google Tag Manager container is configured to call, corroborated by the browser request log. Tools injected only after the page renders, and tools loaded on pages other than the homepage, are outside what this can see. When the HTML we receive is a bot challenge or a client-rendered shell rather than the page, we report the stack as not inspected instead of reporting an empty one. | Live | snapshot | page source |
Tag inventory read from the published Google Tag Manager container Reads the tag configuration your published Google Tag Manager container serves to any visitor, so it needs no account access. It covers only the containers we could fetch and parse, named on the slide, and at most two container ids per page. Tags hardcoded into the page, injected after load, running server-side, or sitting inside a Zone tag's child containers are not in these numbers. A container we could not read is reported as not measured, never as an empty tag stack. Tag names are only shown when the container was published with them, which is not the default: in six of seven containers tested there were none. | Live | snapshot | the container the site publishes to every visitor |
Tags in the container carrying one of GTM's additional consent checks Counts how many tags in the container carry one of GTM's additional consent checks. A count above zero proves consent gating is configured. A count of zero proves nothing at all, because consent mode is set by your consent platform when the page loads and is never stored in the container, so we report that state as not recorded rather than as a gap. This is not a compliance verdict and does not tell you whether your consent setup is lawful. | Live | snapshot | the same container fetch |
Cookies set before any interaction, named with lifetimes Read from the browser's own cookie jar and web storage on one load of the homepage with nothing clicked, 2.5 seconds after load, so it is still a floor in time. Cookies your own domain gained without a Set-Cookie header we recorded are reported as set at runtime. Cookies on a third party's domain are reported as unknown provenance: we never read that host's response headers and will not guess. Cookie values and storage values are never read. | Live | snapshot | Set-Cookie on first response, plus the browser's own cookie jar |
Tracking tags carrying no consent gate, named with the markup as evidence | Live | snapshot | delivered markup |
Consent platform detection across 23 vendors, with tenant id | Live | snapshot | resolved script hosts |
Google Consent Mode version, defaults and call ordering | Live | snapshot | inline script parsing |
US state opt-out link, privacy and cookie policy, GPC, ads.txt, TCF and GPP stubs | Live | snapshot | own fetches |
Duplicate analytics IDs, tag redundancy and tracking coverage across templates Duplicate measurement IDs are detected from tag-loader fetches and pageview hits on a single page load, for Google's loaders and hit formats, and the evidence is printed with the finding. When neither signal is present the check is reported as not run rather than as clean. Tag coverage is reported across the render sample, over the pages that rendered. | Live | snapshot | headless render request log |
Own-funnel conversion events: free-audit-started, deck-viewed, checkout-started, purchase, share-link signup Nine named steps, written server-side from the proxy, the order actions, the deck routes and the worker. Attribution is first-touch and kept for 30 days, so a visitor who arrives on an ad and returns through search stays credited to the ad. Visits are counted once per browser cookie rather than per request, which makes them people-shaped but undercounts anyone clearing cookies and overcounts anyone using two devices. The bot filter is a user-agent match and therefore a floor, so the visit figure is worded as traffic we could not identify as a bot. Ad spend lives in the ad platforms and not here, so cost per customer is a division the reader does. | Live | - | own infra: first-party events table in Postgres, no external analytics service |
Consent enforcement: deny consent and observe what fires anyway, from EU egress Dropped 2026-08-08. The value is entirely in the egress point: whether Reject All is honoured is a question about EU law, and many sites do not serve the EU consent flow to a non-EU IP at all. Our infrastructure is a single VPS in India, so the honest choices were a second box in the EU purely for this check, or a proxy in the request path of an audit. Neither is worth it before a customer asks. What we do ship is the static half: cookies and tags observed before any consent choice, which is a real finding and is never worded as an enforcement test. | Deliberately not built | - | headless render from an EU host |
Content & editorial authority
| Capability | Status | Tier | Source |
|---|---|---|---|
Author bylines, credentials, reviewer attribution and outbound citation counts Detects a named author, stated credentials, a reviewer line and outbound citations. It does not judge whether the credential is real. | Live | snapshot | crawl HTML |
Content freshness distribution bucketed by age Pages with no machine-readable date are reported as unknown age, never as old. | Live | snapshot | JSON-LD dateModified, time elements, visible dates |
Readability bucketed per sentence, not a single document score Reported as sentence length, which is a fact. Flesch Reading Ease is computed but not printed: on a shallow crawl it rated plainlanguage.gov and BBC News harder than a B2B software homepage, so it is not defensible as a headline number. | Live | snapshot | crawl text |
Content quality PASS grid: 5 named URLs against 4 binary criteria with a fix per row Five of your longest editorial pages, judged from the text we could retrieve without running JavaScript. A page whose body renders client-side is left out rather than marked down. | Live | snapshot | crawl + one DeepSeek pass |
Semantic-triplet check quoting the site's own failing sentence beside a rewrite Samples up to 40 prose sentences across the crawled pages, at most 6 per page, and judges each for whether a retrieval system could extract a subject, predicate and object from it. Every sentence printed in the deck is verified to appear verbatim on the page it is attributed to; anything the model paraphrases is discarded rather than shown. Rewrites may name the company as the missing subject and may use no other fact that is not already in the sentence. | Live | professional | DeepSeek over crawled text |
Funnel-stage segmentation with page counts: TOFU, MOFU, BOFU, E-E-A-T Classified from URL shape, so a site with unconventional paths lands pages in unclassified rather than guessing. | Live | snapshot | URL patterns |
Thin content detection Word count only. The quality rubric that judges substance is not built. | Live | snapshot | crawl word counts |
Topical authority: pillar and cluster map, missing high-intent pages Clusters the ranked-keyword sample, which is the top few hundred keywords by modelled traffic out of an index often holding tens of thousands, so a topic held weakly never appears and the ratio of owned to weak topics is biased towards owned by construction. Gap detection walks Google's related-searches graph out from at most five seeds, so it finds what is adjacent to topics already held and is blind to a valuable subject that is not a near neighbour. Absence is verified against the whole index per candidate, capped at ten checks, and the count left unchecked is reported. Clustering is a shared-word rule with a crude stemmer and no synonyms, so car insurance and auto insurance are two topics. | Live | professional | DataForSEO keywords + clustering |
Content hub reachability from primary navigation and footer | Live | snapshot | existing crawl |
Zero-traffic page inventory as a pruning deliverable Crawled pages holding no keyword in the 300 we pulled. On a site with more keywords than we sample, some of these rank somewhere further down the tail, so the finding is worded as absence from the sample rather than absence from the index. | Live | professional | DataForSEO ranked-keywords export, inverted |
Demand & competitive position
| Capability | Status | Tier | Source |
|---|---|---|---|
Competitor set of 5, validated against business classification, selection rule printed Competitors are derived from keyword overlap in one market and one language, so a rival selling elsewhere is invisible and a site that merely shares vocabulary can appear. Ranked by relevance to this site rather than size, because a domain with fifty times the traffic and three shared keywords is not a competitor. | Live | professional | DataForSEO Labs intersected with model-named brands |
Ranked keywords, position bands, estimated traffic and traffic value Pulls the 300 keywords carrying the most estimated traffic, out of however many the index holds, and every rate says which of the two it is calculated over. Estimated traffic is DataForSEO's model of search volume through a click-through curve, not a measurement of the site, and will not match the client's analytics. Rankings are per market: this defaults to the United States and prints the market it used, so a client selling elsewhere can see it looked in the wrong index. | Live | professional | DataForSEO Labs |
Branded versus non-branded keyword split Branded terms are matched by token against the domain and the detected brand name, and the tokens used are printed with the result, so a company whose brand is an ordinary word can see why ordinary searches landed in the branded column. Derived from the same ranked-keyword pull at no extra cost. | Live | professional | brand-token regex over the DataForSEO keyword export |
Keyword gap: terms competitors hold and you do not, sized by opportunity Compares at most four competitors the caller names: it does not discover them, and returns not-measured rather than an empty list when none are supplied. Draws from the highest-traffic gap rows per competitor out of thousands the index holds, so it is a sample of the top and a valuable term further down the tail is missed. It cannot judge topical relevance, so a competitor ranking outside our category still contributes terms. Every value figure is modelled three times over and assumes a new page reaches the bottom of page one, which nothing guarantees: it orders the list and must never be read as revenue. | Live | professional | DataForSEO Labs Domain Intersection |
Backlinks: referring domains by authority band, total links, competitor link gap Reports site-wide totals plus the 100 strongest linking domains by authority. It deliberately publishes no authority distribution: sorted by rank and cut at 100, a band count describes the sort rather than the profile, and on one real domain it put 99 of 100 into a single band. Nothing is described as toxic, because no automated method distinguishes a harmful link from an ordinary weak one, and a long tail of weak domains is normal on every site of any age. | Live | professional | DataForSEO Backlinks |
Search volume, CPC and difficulty for the keyword set Search volume, cost per click and difficulty come with the ranked-keyword pull rather than a separate call. Difficulty is absent for some terms and reported as unknown rather than zero. | Live | professional | DataForSEO Keywords Data |
Organic traffic estimate with the method printed Organic only: we do not estimate total traffic, which needs clickstream data we deliberately do not buy. What is reported is DataForSEO's model of search volume through a click-through curve, not a measurement of the site, and it will not match the client's analytics. Reported with the branded and non-branded split, because branded cost-per-click is what competitors pay to bid against the name and never what the company would pay for its own: on one test that was 80% of the gross figure. When a single keyword carries a quarter or more of the total, the deck names it. | Live | professional | DataForSEO Labs |
Opportunity value: what closing each gap is worth per month Positions 4 to 10 only, modelling a move to position 3 on published average click-through rates. A wider band produced an $84,000-a-month figure for a term held at position 16 by accident, which is a campaign rather than a fix. Near-duplicate keywords are counted once. The averages cover every kind of search at once, so the figures rank opportunities against each other rather than forecast revenue. | Live | professional | DataForSEO keyword volume x CPC x position curve, method printed |
Head-to-head grid against 3 competitors on free checks, with the selection rule printed Twelve checks read each homepage as delivered, for you and up to three competitors. Name them yourself, or we propose them: from your own comparison pages where you publish them, otherwise from a language model reading your page titles and headings, labelled unverified. Anything needing paid data (rankings, backlinks, ad spend) is not in the grid, and a competitor whose site blocks automated requests shows as not measured rather than scored. | Live, with a limit | snapshot | own fetch of each competitor homepage |
New versus lost referring domains over time | On the roadmap | enterprise | DataForSEO Backlinks history |
Paid media: ad presence, paid keywords, creative and estimated spend | On the roadmap | enterprise | DataForSEO paid SERP + public ad libraries |
Which landing pages competitors advertise to | On the roadmap | enterprise | public ad libraries |
Google Ads and LinkedIn Campaign Manager account analysis Incompatible with a URL-only product at any tier. | Deliberately not built | - | OAuth into client ad accounts |
Business context & the deliverable
| Capability | Status | Tier | Source |
|---|---|---|---|
What the business sells, its segments and product taxonomy Described from what the pages themselves state. The model is explicitly barred from inferring revenue, size, funding or market position. | Live | snapshot | DeepSeek over crawled page titles and headings |
Findings as Observation, Impact, Recommendation, Effort, Priority with a category badge Effort is derived from the finding type rather than measured against your codebase, and priority weighs severity against it. CSV export is not built yet. | Live | snapshot | existing findings |
CSV export per finding class, for the team that has to fix it | Live | snapshot | existing findings |
Expert human review before delivery The audit is held rather than delivered until a reviewer releases it, so turnaround depends on a person being available. Releasing rebuilds the deck from the stored facts, so the reviewer can add a note but cannot change a number. | Live | Add-on | a person |
Partner REST API and webhooks for agencies Orders, status, artifacts, brand kits and HMAC-signed webhooks are live, with a sandbox mode. No published rate limit, no durable retry queue past three webhook attempts, and no bulk-order endpoint. | Live | professional | own infra |
Executive summary on a fixed slot schema, slots marked not-measured by tier Written as prose. The fixed seven-slot schema that makes it skimmable is not built. | Live, with a limit | snapshot | DeepSeek over measured facts |
Phased roadmap with a printed sequencing rule and a re-audit close Phases are hardcoded rather than derived, and carry no sequencing rule, KPI or re-audit step. | Live, with a limit | snapshot | findings |
Per-claim source and date disclosure One methodology slide exists. Individual claims do not yet carry their own source tag. | Live, with a limit | snapshot | collector timestamps |
Deck rendered in the client's brand, extracted from a URL or a PPTX template Colours only, and read from the two places a brand colour is stated reliably: a theme-color meta tag or a brand-named CSS variable. We deliberately do not infer it from the colours in the page, so a site declaring neither falls back to our palette unless you supply a hex. Logos and fonts are not yet applied. | Live, with a limit | Add-on | theme-color tag, brand-named CSS variables, or a hex you supply |
Industry module: local, e-commerce, SaaS, publisher or app | On the roadmap | professional | classification + targeted checks |
Subfolder or vertical-scoped audits repeated per business line One reference deck spent 120 of its 213 slides doing exactly this. | On the roadmap | enterprise | repeat the pipeline per scope |
Market sizing, TAM and CAGR Highest embarrassment risk in the corpus. Human add-on only, never automated. | Deliberately not built | Add-on | a person with sources |
Maturity scores out of 10 without a published rubric A label is a score. Any printed band ships its thresholds on the same slide, or it stays a raw count. | Deliberately not built | - | n/a |
Business-value uplift percentages without a live citation Uncited statistics sitting beside measured facts inherit unearned authority. Banned product-wide. | Deliberately not built | - | n/a |
Questions about anything here, or want something prioritised? Email info@auditaar.com.