A website audit can turn into a hundred-point technical report that leaves an owner unsure what matters. This checklist is organized by business risk. Start with ownership and customer contact, then move through access, technical health, content, local visibility, measurement, and maintenance.
A checkmark does not guarantee rankings or leads. It means an important foundation is present and working. Record the owner, evidence, priority, and review date for every item that matters.
1. Ownership and administrative control
- The legal business or authorized owner is the domain registrant.
- The domain uses a business-controlled email, current billing, auto-renew where appropriate, multi-factor authentication, and documented recovery methods.
- At least two trusted people know where access records are stored.
- The business has appropriate administrator access to the website and hosting.
- The business is an owner of its Google Business Profile, Search Console property, analytics, Tag Manager, advertising, and critical integrations.
- Providers use named user or manager accounts instead of shared passwords where roles are available.
- The contract defines ownership of copy, photography, logos, design files, code, customer data, and licensed assets.
- Export, cancellation, transition, and data-retention terms are documented.
2. Domain, hosting, security, and recovery
- The preferred domain resolves consistently, and alternate versions redirect correctly.
- All public pages use HTTPS without mixed-content warnings.
- Software, plugins, themes, and server components are supported and updated through a controlled process.
- Administrator accounts use strong unique passwords and multi-factor authentication.
- Backups include the content, media, configuration, and database needed for restoration.
- Backups are stored separately from the live site and retained for a useful period.
- A restore has been tested, not merely assumed.
- Someone receives uptime, security, certificate, and backup-failure alerts and knows what to do.
- Form and customer data are collected only when needed, protected appropriately, and retained intentionally.
3. Mobile usability and page experience
- The design responds cleanly across common phone, tablet, and desktop widths.
- Text is readable without zooming; buttons and links are easy to tap.
- The primary phone number is clickable and not covered by popups or chat widgets.
- Navigation reveals priority services and contact options quickly.
- Forms use clear labels, useful error messages, appropriate input types, and reasonable field counts.
- Important information on desktop is also available on mobile.
- Pages avoid intrusive interstitials and distracting movement.
- Core Web Vitals and other performance findings are reviewed in field data where available, with customer-facing problems prioritized over a perfect score.
- Large images are sized and compressed appropriately; unnecessary scripts and widgets are challenged.
4. Accessibility basics
WCAG 2.2 is the current W3C recommendation. Accessibility requires human judgment as well as tools; do not claim conformance from an automated scan alone.
- Pages use a logical heading structure with one descriptive main heading.
- Keyboard users can reach interactive controls in a sensible order and see focus.
- Links and buttons have understandable names rather than repeated vague labels.
- Images that convey information have useful text alternatives; decorative images are treated appropriately.
- Color contrast is sufficient, and meaning is not conveyed by color alone.
- Forms have programmatic labels, instructions, error identification, and status messages.
- Video has captions when needed; audio information has an accessible alternative.
- Target sizes, zoom, reflow, motion, and focus-obscuring overlays are reviewed.
- Critical tasks are tested manually with keyboard and relevant assistive technology or specialist review when risk warrants it.
5. Crawlability and indexability
- Important public pages are not blocked by robots.txt, noindex, login requirements, or security tools.
- Each indexable page returns the intended status and has a sensible canonical URL.
- Old or changed URLs use direct redirects to the most relevant current page.
- The XML sitemap contains preferred indexable URLs and is submitted in Search Console.
- Navigation and internal links allow users and crawlers to find priority pages.
- Duplicate, filtered, staging, printer, and tracking-parameter URLs are handled intentionally.
- Search Console ownership is verified and Coverage or indexing issues are reviewed in context.
6. Titles, headings, and on-page clarity
- Each important page has a unique descriptive title that matches its purpose.
- The main heading clearly summarizes the page without exaggeration.
- Subheadings help a reader scan decisions, process, proof, limitations, and next steps.
- The primary answer appears early; introductions do not delay it with generic marketing language.
- Meta descriptions are accurate invitations, not stuffed keyword lists or ranking claims.
- Images, captions, filenames, and alt text describe content naturally where useful.
- Structured data, if used, matches visible information and current Google documentation.
7. Service and business content
- The homepage states what the business does, who it helps, where it works, and what to do next.
- Each priority service has enough accurate information to support a customer decision.
- The site explains scope, process, common questions, limitations, and realistic expectations.
- Project photos and examples are real, current, approved, and given useful context.
- Credentials, licenses, insurance, awards, partnerships, and experience claims are verified and current.
- The About page identifies the real business or accountable owner without inventing a team or history.
- Policies, contact information, hours, and service areas are current.
- Overlapping pages are combined or differentiated so they do not compete unnecessarily.
8. Local SEO and Google Business Profile
- The Business Profile is verified and owned by the business, with providers added as managers where appropriate.
- The name, primary category, additional categories, address or service area, phone, website, and hours accurately represent the real business.
- No keywords are added to the profile name unless they are part of the real-world business name.
- No fake offices, virtual locations, P.O. boxes, or duplicate profiles are used.
- Services, attributes, photos, holiday hours, and other relevant details are maintained.
- The website and major listings do not contain meaningful conflicts in business information.
- Service-area pages are useful and distinct, not copied town-name swaps.
- Local citations prioritize accurate, relevant platforms, associations, chambers, suppliers, and industry resources over bulk directory counts.
- Legitimate local links and mentions are earned through real relationships and useful resources.
9. Reviews and reputation
- The business has a consistent process to ask real customers for honest reviews.
- No discounts, gifts, or other incentives are offered for reviews.
- The process does not filter customers or selectively request only positive reviews.
- Reviews receive privacy-conscious, professional responses.
- Recurring criticism is routed into operations rather than treated only as a marketing problem.
- Review widgets and quotations identify the source accurately and comply with platform terms.
10. Conversion and lead handling
- Every important page offers a next step suited to visitor intent.
- Click-to-call, email, forms, scheduling, donation, or purchase actions work on mobile and desktop.
- Forms are tested through submission, confirmation, delivery, CRM entry, notification, and follow-up.
- The visitor is told what happens next and when a response is reasonable.
- Urgent and planned services have different contact paths when appropriate.
- Trust evidence appears near the decision, not only on a separate page.
- Service-area and fit requirements reduce wasted inquiries without sounding hostile.
- Missed calls and after-hours inquiries have an intentional handling process.
11. Analytics, Search Console, and measurement
- Analytics and Search Console use business-controlled accounts and correct properties.
- Meaningful events such as completed forms, click-to-call actions, appointments, donations, or purchases are configured and tested.
- Internal traffic, spam, and duplicate events are understood or filtered where practical.
- The business can connect important inquiries to landing pages or channels without claiming perfect attribution.
- Reports distinguish visibility, engagement, conversions, lead quality, and business outcomes.
- Seasonality, location, service mix, and operational capacity are considered.
- A baseline is recorded before redesign, migration, or SEO work.
12. AI-search readiness
Google states that the same SEO fundamentals support AI Overviews and AI Mode. There is no special schema, AI text file, or guaranteed optimization that secures a citation.
- Important information is crawlable, indexable, available as text, and linked internally.
- Pages answer the main question clearly and add non-commodity experience or analysis.
- Business Profile and website facts are accurate and current.
- Structured data is accurate but is not treated as an AI-visibility shortcut.
- Content creation has human accountability, source verification, and an update process.
- Generative AI visibility reports in Search Console are reviewed if available to the property; rollout availability may vary.
- Measurement considers qualified visits and actions, not only clicks or raw impressions.
13. Maintenance schedule
Monthly
- Test priority forms, phone links, scheduling, and lead delivery.
- Review security, backup, uptime, and update alerts.
- Check Business Profile changes, hours, new reviews, and messages or features actually used.
- Review qualified inquiries and obvious analytics or Search Console anomalies.
Quarterly
- Review top services, landing pages, search queries, conversions, and lead quality.
- Update project evidence, photos, FAQs, staff or owner details, and service information.
- Check access lists, integrations, licenses, and recurring subscriptions.
- Run accessibility, performance, broken-link, and indexability checks on priority journeys.
Annually and after major change
- Verify domain contacts, renewal, ownership register, recovery methods, and contracts.
- Test a backup restore and document the result.
- Audit content overlap, outdated claims, prices, policies, locations, and citations.
- Reassess whether the platform and support plan still fit the business.
How to prioritize the findings
- 1.Fix ownership, security, broken lead paths, and false business information first.
- 2.Then address crawl and index blocks, mobile barriers, accessibility issues in critical tasks, and severe performance problems.
- 3.Improve priority service content, proof, local relevance, and calls to action.
- 4.Add measurement and an achievable maintenance rhythm.
- 5.Treat optional features, perfect scores, and speculative AI tactics as lower priority unless evidence says otherwise.
Turn the checklist into a working plan
Assign each failed item an owner, evidence, priority, cost range, and target date. A short completed plan is more valuable than a long audit that nobody acts on. TechDad Technology can help a New Hampshire, Vermont, or Maine small business review this foundation, explain the tradeoffs, and handle the pieces that do not fit into the owner's day.


