Skip to main content
Back to Audits • REF: sample-previ Sample Preview Data
Technical & On-Page SEO Audit Oct 8, 2026

example-ecommerce.com

Point-in-time assessment of the public pages and tools listed below. Findings, measured checks, and tool limitations are reported separately.

Target URL: https://example-ecommerce.com
Pages Scanned: 18
88 Out of 100
B+ Search Readiness
46 of 50 evaluated checkpoints passed
Total Checks 50
Passed Checks 46
Critical / High 1
Moderate / Warnings 2
Low / Info 1
Perimeter Checkpoint Verification: 92% Pass Rate

Category Scorecard & Pillar Breakdown

Security & Response Headers Hardened
94% 12/12 passed

Strong cryptographic posture

Technical Crawlability & SEO Needs Action
86% 14/16 passed

Missing Schema.org JSON-LD rich snippets

Speed & Core Web Vitals Bottleneck
76% 6/8 passed

Mobile LCP > 3.4s on uncompressed hero

Accessibility & Semantics Notice
88% 8/9 passed

4 image elements missing descriptive alt tags

Lighthouse CI scores

Lab scores from this audit run, on a 0–100 scale. These measurements are not field Core Web Vitals.

https://example-ecommerce.com/

Performance
76/100
Accessibility
88/100
Best practices
92/100
SEO
86/100

Prioritized Audit Findings & Developer Remediation

Prioritized by severity with observed evidence and suggested remediation. Review example configuration against your deployment before use.

find-lcp-1 high reliability Source: playwright

Slow LCP (3.8s) Caused by Uncompressed Hero Banner

https://example-ecommerce.com/

Security & SEO Impact: Drastically lowers mobile search rankings and increases bounce rate on primary entry pages.

Show Measured Scanner Evidence
Hero image payload is 2.4 MB uncompressed PNG without fetchpriority='high' or preload tag.
HTML Inject high-priority preload in <head>:
<link rel="preload" as="image" href="/assets/hero-banner.webp" fetchpriority="high" type="image/webp" />

Direction: Convert hero banner from PNG to modern AVIF/WebP with priority loading fetchpriority='high'.

find-schema-1 medium seo Source: playwright

Missing LocalBusiness & Organization Schema (JSON-LD)

https://example-ecommerce.com/

Security & SEO Impact: Misses Google Map Pack ranking boost and rich knowledge graph search snippets.

Show Measured Scanner Evidence
No application/ld+json blocks found in homepage HTML head or body.
HTML Inject Schema.org JSON-LD in <head>:
<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "ProfessionalService",
  "name": "example-ecommerce.com",
  "url": "https://example-ecommerce.com",
  "description": "Comprehensive technology and digital services provider.",
  "telephone": "+1-800-555-0199",
  "address": {
    "@type": "PostalAddress",
    "streetAddress": "123 Business Way",
    "addressLocality": "City",
    "addressRegion": "ST",
    "postalCode": "12345",
    "addressCountry": "US"
  }
}
</script>

Direction: Inject JSON-LD structured data with name, address, telephone, and social entities.

find-canonical-1 medium seo Source: playwright

Duplicate Non-Canonical URLs in Faceted Navigation

https://example-ecommerce.com/catalog

Security & SEO Impact: Dilutes page authority and wastes Googlebot crawl budget across parameterized filter URLs.

Show Measured Scanner Evidence
Filter query parameters (?sort=price&filter=new) lack self-referencing canonical tag.
HTML Enforce clean root canonical in <head>:
<link rel="canonical" href="https://example-ecommerce.com/catalog" />

Direction: Implement self-referencing canonical tags on category roots and disallow filter parameters in robots.txt.

find-alt-1 low accessibility Source: playwright

Images Lack Descriptive Alternative Text

https://example-ecommerce.com/about

Security & SEO Impact: Fails WCAG 2.1 AA accessibility guidelines and misses image search visibility.

Show Measured Scanner Evidence
4 images found with missing alt attribute on team page.
HTML Provide descriptive alt text:
<img src="/assets/team-director.webp" alt="Senior Technical Director leading cloud migration session" width="400" height="300" />

Direction: Add descriptive alt attributes or empty alt='' for decorative assets.

Full technical report

The same in-depth sections as the PDF: 4 grouped issues, 6 checkpoints, and 4 page profiles.

Audit at a glance

4 unique issue groups · 4 recorded occurrences. Repeated detections are consolidated into issues; occurrences remain evidence records.

Charts summarize reported evidence, not proof that unreported issues are absent. Only in-scope categories are shown.

Category scores

CategoryScore (0–100)Measured checksUnverified checksPassed / planned
Security & Response Headers94/100Security & Response Headers: 94 of 1002012/12
Technical Crawlability & SEO86/100Technical Crawlability & SEO: 86 of 1003014/16
Speed & Core Web Vitals76/100Speed & Core Web Vitals: 76 of 100106/8
Accessibility & Semantics88/100Accessibility & Semantics: 88 of 100008/9

Measured checks include passed and failed outcomes. Scores reflect the report scoring method; check coverage is shown separately.

Severity distribution

Unique issues by severity: critical 0, high 1, medium 2, low 1, info 04unique issues
SeverityUnique issuesRecorded occurrences
critical0critical: 0 unique issues0
high1high: 1 unique issues1
medium2medium: 2 unique issues2
low1low: 1 unique issues1
info0info: 0 unique issues0

The ring shows the share of unique issues by severity. Bar lengths compare unique issue counts. Occurrences include repeated observations and are not additional unique issues.

Most repeated issues
IssueOccurrencesAffected URLs
Slow LCP (3.8s) Caused by Uncompressed Hero Banner
reliability · high
1Slow LCP (3.8s) Caused by Uncompressed Hero Banner: 1 occurrences1
Duplicate Non-Canonical URLs in Faceted Navigation
seo · medium
1Duplicate Non-Canonical URLs in Faceted Navigation: 1 occurrences1
Missing LocalBusiness & Organization Schema (JSON-LD)
seo · medium
1Missing LocalBusiness & Organization Schema (JSON-LD): 1 occurrences1
Images Lack Descriptive Alternative Text
accessibility · low
1Images Lack Descriptive Alternative Text: 1 occurrences1

Top 4 of 4 groups, ranked by recorded occurrences. Repetition does not imply higher severity.

Page issue heatmap

PageSecurity & Response HeadersTechnical Crawlability & SEOSpeed & Core Web VitalsAccessibility & Semantics
https://example-ecommerce.com/01
medium
1
high
0
https://example-ecommerce.com/about0001
low
https://example-ecommerce.com/catalog01
medium
00
https://example-ecommerce.com/contact0000
https://example-ecommerce.com/services0000

Showing 5 of 5 URLs with the highest unique issue burden. Each cell counts unique groups once per URL, including repeated page observations. Color and text indicate the highest severity. 0 means no reported findings, not a passed check. Categories outside the audit scope are omitted.

Remediation roadmap

Phase 1 — Immediate (0–7 days)

Critical and high-severity issues that expose users or block search and availability.

  • F-01 high Slow LCP (3.8s) Caused by Uncompressed Hero Banner · 1 page(s) · effort Medium

Phase 2 — Short term (within 30 days)

Medium-severity hardening, accessibility barriers, and search-visibility gaps.

  • F-02 medium Duplicate Non-Canonical URLs in Faceted Navigation · 1 page(s) · effort Medium
  • F-03 medium Missing LocalBusiness & Organization Schema (JSON-LD) · 1 page(s) · effort Medium

Phase 3 — Planned (within 90 days)

Low-severity improvements and best-practice alignment.

  • F-04 low Images Lack Descriptive Alternative Text · 1 page(s) · effort Medium

Ongoing — Review and monitor

Informational observations, manual-review items, and re-testing after each release.

No issues in this phase.

Checkpoint results

Unverified means the supporting tool did not complete or evidence was insufficient; it never counts as a pass.

AreaCheckpointOutcomeWhat a pass means
security Strict HTTPS Encryption Across All Pages passed All visited pages enforce HTTPS encryption with valid TLS 1.3 certificates.
security Clickjacking Defense (X-Frame-Options: DENY) passed Valid framing restriction stops hostile iframe overlay attacks.
seo Robots.txt Directive Hygiene passed Clean robots.txt file cleanly guides search bots without blocking valid indexable routes.
seo XML Sitemap Availability & Hygiene passed Sitemap is declared and contains valid indexable 200 URLs.
seo Unique Page Title Tags (< 60 Characters) passed Target pages define clear, non-duplicate titles under 60 characters.
performance Server Response Time & Fast TTFB passed Initial edge time-to-first-byte measured under 320ms.

Security posture

Findings
0 critical · 0 high · 0 medium · 0 low · 0 info
Pages served over HTTPS
4 of 4
Pages with all 8 core security headers
0 of 4
Pages with insecure resource references
0 of 4
Client-side libraries detected
none
Third-party script hosts
fonts.gstatic.com, www.googletagmanager.com
HeaderCoverageObserved (sample)Purpose & recommendation
strict-transport-security 4/4 max-age=31536000 Forces browsers to use HTTPS for the host and blocks SSL-stripping attacks.
Recommended: max-age=31536000; includeSubDomains (add preload after verifying every subdomain).
content-security-policy 0/4 not observed Restricts where scripts, styles, frames, and connections may load from; the main XSS mitigation.
Recommended: default-src 'self'; script-src with nonces or hashes; object-src 'none'; base-uri 'self'; frame-ancestors 'self'.
x-content-type-options 4/4 nosniff Stops MIME sniffing so responses are only interpreted as their declared type.
Recommended: nosniff
x-frame-options 0/4 not observed Legacy clickjacking defense; superseded by CSP frame-ancestors.
Recommended: DENY or SAMEORIGIN (and CSP frame-ancestors).
referrer-policy 4/4 strict-origin-when-cross-origin Controls how much of the URL is sent to other sites in the Referer header.
Recommended: strict-origin-when-cross-origin
permissions-policy 0/4 not observed Disables powerful browser features (camera, microphone, geolocation) the site does not use.
Recommended: camera=(), microphone=(), geolocation=(), payment=()
cross-origin-opener-policy 0/4 not observed Isolates the browsing context from cross-origin windows (Spectre-class and tab-nabbing defenses).
Recommended: same-origin (or same-origin-allow-popups when OAuth popups are used).
cross-origin-resource-policy 0/4 not observed Prevents other origins from embedding the resource.
Recommended: same-origin for private resources; same-site or cross-origin only where needed.
cross-origin-embedder-policy 0/4 not observed Required for cross-origin isolation; only needed for advanced APIs such as SharedArrayBuffer.
Recommended: require-corp when cross-origin isolation is needed; otherwise optional.
cache-control 0/4 not observed Controls browser and CDN caching of the HTML document.
Recommended: Use no-store for personalized pages; short max-age with revalidation for public HTML.

0 grouped issue(s) in this area — see grouped findings below.

Search visibility & technical SEO

Findings
0 critical · 0 high · 2 medium · 0 low · 0 info
Pages with a title of 15–60 characters
4 of 4
Pages with a 50–160 character description
0 of 4
Pages with a self-referencing canonical
4 of 4
Pages with exactly one H1
4 of 4
Pages with a mobile viewport
4 of 4
Pages with Open Graph title and image
0 of 4
Pages declaring a language
4 of 4
Median visible word count
775
PageTitleDesc.CanonicalH1WordsLangViewportOGJSON-LD
https://example-ecommerce.com/ 28 29 self 1 640 en yes no —
https://example-ecommerce.com/services 44 29 self 1 730 en yes no —
https://example-ecommerce.com/about 32 26 self 1 820 en yes no —
https://example-ecommerce.com/contact 31 28 self 1 910 en yes no —

2 grouped issue(s) in this area — see grouped findings below.

Performance & reliability

Findings
0 critical · 1 high · 0 medium · 0 low · 0 info
Median time to first byte
240 ms
Slowest time to first byte
300 ms
Median full load
2100 ms
Average page weight
1021 KiB
Heaviest page
1240 KiB
Average requests per page
47
Pages over HTTP/2 or HTTP/3
4 of 4
Pages with console errors
0 of 4
PageTTFBDOM readyLoadKiBRequestsProtocol3rd-party hostsConsole errors
https://example-ecommerce.com/ 180 ms 900 ms 1800 ms 801 38 h2 2 —
https://example-ecommerce.com/services 220 ms 1020 ms 2000 ms 947 44 h2 2 —
https://example-ecommerce.com/about 260 ms 1140 ms 2200 ms 1094 50 h2 2 —
https://example-ecommerce.com/contact 300 ms 1260 ms 2400 ms 1240 56 h2 2 —

1 grouped issue(s) in this area — see grouped findings below.

Accessibility

Findings
0 critical · 0 high · 0 medium · 1 low · 0 info
Pages with images missing alt
1 of 4
Pages with skipped heading levels
0 of 4
Pages with unlabeled form fields
0 of 4
Pages with links lacking text
0 of 4
Pages declaring a language
4 of 4
PageLangMissing altSkipped headingsUnlabeled fieldsLinks without text
https://example-ecommerce.com/ en 0 0 — —
https://example-ecommerce.com/services en 0 0 — —
https://example-ecommerce.com/about en 2 0 — —
https://example-ecommerce.com/contact en 0 0 — —

1 grouped issue(s) in this area — see grouped findings below.

Grouped findings with affected pages

F-01 high reliability · playwright · 1 page(s) · 1 occurrence(s) · effort Medium · Immediate (0–7 days)

Slow LCP (3.8s) Caused by Uncompressed Hero Banner

Hero image payload is 2.4 MB uncompressed PNG without fetchpriority='high' or preload tag.

Recommended action: Convert hero banner from PNG to modern AVIF/WebP with priority loading fetchpriority='high'.

Verify the fix: Re-run Lighthouse or PageSpeed Insights and compare the metric against this report's baseline.

Affected URLs (1)
  • https://example-ecommerce.com/
F-02 medium seo · playwright · 1 page(s) · 1 occurrence(s) · effort Medium · Short term (within 30 days)

Duplicate Non-Canonical URLs in Faceted Navigation

Filter query parameters (?sort=price&filter=new) lack self-referencing canonical tag.

Recommended action: Implement self-referencing canonical tags on category roots and disallow filter parameters in robots.txt.

Verify the fix: Inspect the URL in Google Search Console and confirm the rendered HTML contains the fix.

Affected URLs (1)
  • https://example-ecommerce.com/catalog
F-03 medium seo · playwright · 1 page(s) · 1 occurrence(s) · effort Medium · Short term (within 30 days)

Missing LocalBusiness & Organization Schema (JSON-LD)

No application/ld+json blocks found in homepage HTML head or body.

Recommended action: Inject JSON-LD structured data with name, address, telephone, and social entities.

Verify the fix: Inspect the URL in Google Search Console and confirm the rendered HTML contains the fix.

Affected URLs (1)
  • https://example-ecommerce.com/
F-04 low accessibility · playwright · 1 page(s) · 1 occurrence(s) · effort Medium · Planned (within 90 days)

Images Lack Descriptive Alternative Text

4 images found with missing alt attribute on team page.

Recommended action: Add descriptive alt attributes or empty alt='' for decorative assets.

Verify the fix: Re-run axe DevTools on the page and verify with keyboard navigation and a screen reader (NVDA or VoiceOver).

Affected URLs (1)
  • https://example-ecommerce.com/about

Methodology & scoring

ToolStandardOutcomeFindingsScope
playwright
Headless Chromium crawl of every in-scope page: status, metadata, headings, links, security headers, timing, resource weight, console errors, and client-side libraries.
Browser-observed evidence completed 4 18 pages observed; 0 pages failed; bounded crawl, no authenticated paths or active attacks.
robots.txt
Crawler directives, site-wide blocking, and sitemap references.
RFC 9309 completed 0 Bounded robots inventory observed; sitemap directives sampled.
sitemap.xml
XML sitemap inventory used to seed page discovery.
sitemaps.org protocol completed 0 1 bounded sitemap document observed; 18 same-origin URLs queued before crawling.
  • Each in-scope checkpoint passes only when its tool completed and the observed evidence supports a pass; missing or partial measurements count as unverified, never as passed.
  • Findings that do not map to a checkpoint add to the number of considered checks.
  • The overall score averages the checkpoint pass rate with a severity-weighted deduction (critical 14, high 7, medium 3.5, low 1.2 points; capped per severity). Partial coverage deducts 3 points.
  • Performance-only audits use the mean Lighthouse lab performance score of the sampled pages.
  • Grades: A+ ≥ 97, A ≥ 93, A− ≥ 90, B+ ≥ 87, B ≥ 83, B− ≥ 80, C+ ≥ 77, C ≥ 73, C− ≥ 70, D ≥ 60, F < 60.
  • Lighthouse and PageSpeed Insights lab scores are single-run measurements; real-user data from the Chrome UX Report can differ.

Page-by-page detail

P-01 https://example-ecommerce.com/ HTTP 200 · 2 issue(s)
Title
Home — example-ecommerce.com (28 chars)
Description length
29 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
640
Language
en
TTFB
180 ms
Load
1800 ms
Transferred
801 KiB
Requests
38
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-02 https://example-ecommerce.com/services HTTP 200 · 0 issue(s)
Title
Services & Solutions — example-ecommerce.com (44 chars)
Description length
29 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
730
Language
en
TTFB
220 ms
Load
2000 ms
Transferred
947 KiB
Requests
44
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-03 https://example-ecommerce.com/about HTTP 200 · 1 issue(s)
Title
About Us — example-ecommerce.com (32 chars)
Description length
26 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
820
Language
en
TTFB
260 ms
Load
2200 ms
Transferred
1094 KiB
Requests
50
Protocol
h2
Images / missing alt
8 / 2
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

P-04 https://example-ecommerce.com/contact HTTP 200 · 0 issue(s)
Title
Contact — example-ecommerce.com (31 chars)
Description length
28 chars
Canonical
self
Headings h1–h6
1 / 4 / 6 / 0 / 0 / 0
Words
910
Language
en
TTFB
300 ms
Load
2400 ms
Transferred
1240 KiB
Requests
56
Protocol
h2
Images / missing alt
8 / 0
Scripts
—
Security headers
3 of 8
Console errors
—
Failed resources
—

Third-party hosts: fonts.gstatic.com, www.googletagmanager.com

Glossary

CSP
A response header (Content-Security-Policy) that limits which sources may run scripts or load content.
HSTS
HTTP Strict Transport Security: tells browsers to use HTTPS only for a host.
TLS
Transport Layer Security: the encryption protocol behind HTTPS.
SPF / DKIM / DMARC
Email authentication standards that stop others from sending mail as your domain.
CAA
DNS record naming the certificate authorities allowed to issue certificates for the domain.
DNSSEC
Cryptographic signing of DNS answers to prevent spoofing.
SRI
Subresource Integrity: a hash on a script tag so a modified third-party file is refused.
CWE
Common Weakness Enumeration: MITRE's catalog of software weakness types.
OWASP Top 10
The Open Worldwide Application Security Project's list of the most critical web risks.
WCAG
Web Content Accessibility Guidelines; Level AA is the common legal benchmark.
TTFB
Time to First Byte: delay before the server starts sending the page.
LCP
Largest Contentful Paint: when the main content becomes visible (good ≤ 2.5 s).
CLS
Cumulative Layout Shift: visual stability while loading (good ≤ 0.1).
TBT / INP
Total Blocking Time (lab) and Interaction to Next Paint (field): responsiveness to input.
Canonical URL
The preferred URL for a page when duplicates exist.
Structured data
Machine-readable JSON-LD describing page content for search engines.
Open Graph
Metadata that controls link previews on social and messaging apps.
Lab vs field data
Lab data is a controlled single test; field data is measured from real visitors.

Scan Scope & Tool Coverage Transparency

This automated assessment reviewed 18 public pages. Passive scanning only; no active attacks or credential brute-forcing executed. Point-in-time review does not certify full compliance or replace comprehensive manual penetration testing.

playwright completed

18 pages observed; 0 pages failed; bounded crawl, no authenticated paths or active attacks.

robots.txt completed

Bounded robots inventory observed; sitemap directives sampled.

sitemap.xml completed

1 bounded sitemap document observed; 18 same-origin URLs queued before crawling.

Turnkey Remediation Engineering

Need Help Implementing These Fixes?

Our senior engineering team at R5 Industries provides dedicated remediation sprints to deploy all HTTP response headers, configure Cloudflare zero-trust rules, resolve Core Web Vitals bottlenecks, and inject schema markup for you.

Engineering Retainer Benefits:

  • Performance review and measured improvement plan
  • Zero-trust Cloudflare WAF & CSP deployment
  • Validated Schema.org rich snippets injection
  • Free post-remediation verification re-audit