Four layers, in this order: whether a crawler can read the site, whether it loads inside the thresholds Google publishes, whether a real visitor can use it, and whether a request for service reaches a human. Automated reports cover the first two well, the third partly, and the fourth not at all.
That last gap is the whole problem with audit reports. The machine-readable layers produce a long, satisfying list of defects. The layer that decides whether you get the job produces nothing, because no scanner can tell whether anyone picked up.
robots.txt, canonical tags, HTTPS, titles and headings. A crawler either reaches your pages or it does not.
The three Core Web Vitals, measured against published thresholds on real Chrome traffic, not a lab guess.
Contrast, labels, alt text. The failures that stop a person who is already on the page and ready to ask.
What happens in the minutes after a form submit or a call. Not scannable, and the only layer with revenue attached.
What does a crawler see before it sees your design?
A handful of files and tags, and nothing else. Your robots.txt, your canonical tag, whether the page is served over HTTPS, and whether it has a title and a real first heading.
Across the 16,213,084 sites in HTTP Archive’s 2025 dataset, these checks are mostly healthy and occasionally not. Requests for robots.txt returned a valid 200 for 84.9% of sites, while 13.2% of mobile sites returned a 404 for it. Canonical tags appeared on 67% of mobile pages. Title tags were close to universal at 98.5%, but an h1 was present on only 70% of mobile pages and non-empty on 66%. Meta descriptions appeared on 67.2%.
HTTPS has stopped being a finding worth celebrating: 91.5% of mobile pages used it in 2025, and the Web Almanac’s own reading is that it now functions less as a differentiator and more as a baseline expectation. If an audit report leads with "you have HTTPS," it is padding.
What matters in this layer is narrow. A robots.txt that returns a 200 only proves the file exists; it says nothing about whether its directives are correct. An audit that stops at "file present" has checked a box, not a risk.
What does "slow" mean in an audit report?
Three specific numbers, published by Google, measured on real visits rather than a test run. Largest Contentful Paint should happen within 2.5 seconds, Interaction to Next Paint should be 200 milliseconds or less, and Cumulative Layout Shift should be 0.1 or less, all assessed at the 75th percentile of page loads and split between mobile and desktop.
That is the whole definition, and it comes from Google’s own documentation rather than from any tool vendor. A page passes if it meets all three targets at that percentile.
Most sites do not. In 2025, 48% of mobile sites and 56% of desktop sites had good Core Web Vitals, up from 44% and 55% in 2024. The uncomfortable detail for a service business is which page fails: home pages scored 45% good on mobile against 56% for secondary pages, which the Web Almanac attributes to home pages being updated more often and carrying more dynamic and varied components than templated inner pages.
HTTP Archive, Web Almanac 2025 (16,213,084 sites from the Chrome UX Report)
View data
| Item | Value |
|---|---|
| Desktop, all pages | 56% |
| Mobile, secondary pages | 56% |
| Mobile, all pages | 48% |
| Mobile, home pages | 45% |
Broken out by metric, mobile loses on loading and interactivity rather than stability: 62% of mobile sites hit good LCP, 77% good INP, and 81% good CLS. So when a report says your site is slow, the useful follow-up is which of the three, on which device, and on which page. "Slow" with no metric attached is not a finding.
Does an audit check whether a real person can use the page?
The good ones do, and this is where the failure rate is highest by far. WebAIM’s February 2026 evaluation of the top 1,000,000 home pages found detected WCAG 2 failures on 95.9% of them, up from 94.8% in 2025 and reversing six consecutive years of small improvements.
The volume is going the wrong way too. The scan detected 56,114,377 distinct errors, an average of 56.1 per home page, 10.1% more than the 51 per page found in 2025. Average home page complexity rose 14.3% in a year to 1,437 elements, so pages are growing faster than anyone is fixing them.
Six issue types accounted for 96% of everything detected: low contrast text on 83.9% of home pages, missing image alt text on 53.1%, missing form input labels on 51%, empty links on 46.3%, empty buttons on 30.6%, and missing document language on 13.5%. The same six have topped the list for seven years running.
Read that list as an owner and one line should stop you. Home pages carried 6.9 form inputs on average, and 33.1% of those inputs were not properly labeled. The form is where your leads come from. One input in three on it is unlabeled, which means a screen reader, an autofill routine, and often a confused thumb on a phone all get less to work with than your designer assumed.
Two honest caveats, because WebAIM states them itself. It used the WAVE engine on the rendered DOM after scripts and styles were applied, so this is not a raw-HTML artifact. And automated tools cannot catch every conformance failure, which means the absence of detected errors does not prove a page is accessible, and true full conformance was certainly below 4.1%.
Which check actually decides whether the phone rings?
The one no scanner performs: what happens in the minutes after someone contacts you. You test it by hand, on your own site, using your own phone.
This is the layer where audits go quiet and businesses lose money. A contact form can validate perfectly, return a thank-you page, and deliver to a mailbox nobody opens. A click-to-call link can point at a number that forwards to a voicemail that was full in March. Every one of those passes an automated check.
- 01Submit your own formFrom a phone, on cellular data, not the office wifi. Use a real email you can check.
- 02Start a timerNote when the first reply arrives, and whether it came from a person or from nothing at all.
- 03Call the number on the pageAfter hours, on a weekend. Count the rings, then listen to whatever answers.
- 04Write down both numbersMinutes to first reply, and whether the call reached a human. That pair is your real audit score.
Response time is its own subject, and the data on it is less tidy than the folklore suggests. We went through it separately in how fast you have to answer a new lead. For the purposes of an audit, the point is narrower: this is the only layer with revenue directly attached, and it is the only one a report cannot fill in.
Does a website audit still matter if AI answers the question first?
It matters for a different reason than it did five years ago. Fewer searches send a visit at all, which raises the value of each one that does arrive.
In the first four months of 2026, 68.01% of US Google searches ended without a click, up from 60.45% in 2024, based on Similarweb’s desktop and mobile web clickstream panel as analyzed by SparkToro. AI Overviews appeared on more than 20% of searches and cut click-through rate by nearly 60% when present. One stated limitation to carry with that figure: the panel covers mobile searches in a browser and does not include the Google mobile search app, where the authors note zero-click behavior is likely more aggressive still.
The practical consequence is not "stop maintaining your site." It is that your pages now do two jobs: they answer the person who clicked, and they supply the text that answering engines quote when nobody clicks. Both jobs reward the same things an audit checks. Readable HTML, real headings, plain language answers near the top of the page, and facts stated in text rather than locked inside an image.
Structured data is worth a sober look here. It appeared on 50% of home pages in 2025, with JSON-LD at 43%. Google’s own guidance on generative AI search warns against overfocusing on it: structured data is not required for generative AI search, there is no special markup to add for it, and its stated value remains eligibility for rich results in Search. Which types earn a rich result changes without notice, as it did when Google retired FAQ rich results.
What will a website audit not tell you?
Whether the site makes money. An audit produces a list of defects; it does not rank them by revenue, and most reports quietly imply that fixing the list fixes the business.
Google is unusually direct about the limits on its side. Its page experience documentation states that there is no single page experience signal, that Core Web Vitals are used by its ranking systems, and that good results in a Core Web Vitals report do not put your pages at the top of Search. The same page says that aspects of page experience beyond Core Web Vitals do not directly help a page rank higher, and that chasing a perfect score for SEO reasons may not be the best use of your time.
So two findings can sit side by side on the same report with wildly different worth. "Your h1 is empty" is real, cheap, and worth ten minutes. "Your mobile LCP sits in the poor band, past 4 seconds" is real and expensive, and for a service company whose buyers arrive from a map listing and a phone call, it may still rank below "the after-hours line goes to a voicemail nobody checks."
How do you read an audit report without buying the wrong fix?
Run every finding through three questions, in order, and let the ones that fail all three sit at the bottom of the list where they belong.
- 01Which number in my business changes if this is fixed?Calls answered, forms delivered, booked jobs. If the honest answer is "none, but the score goes up," it is housekeeping.
- 02Is this measured on real visits or on a lab test?Core Web Vitals come from real Chrome traffic at the 75th percentile. A one-off synthetic score on an office connection is a hint, not a measurement.
- 03Is it on the path between a stranger and a booked job?Find the page, read the page, submit the form, get a reply. Defects on that path outrank everything else on the report.
For a service company owner past $2M, the ranked list usually comes out in a boring order. First, anything that blocks indexing, because a page a crawler cannot reach earns nothing. Second, anything broken on the contact path, because that is where paid and organic demand both land. Third, the accessibility failures on the form itself, which are cheap and sit directly on that path. Fourth, speed on the pages that actually receive traffic. Everything else is maintenance, done when a developer is already in the file.
If you want the machine-readable half run on your own domain, that is what our site check does: indexability, speed, the contact elements it can see, and your Google listing. The phone test above is still yours to run. It is the half that decides whether any of the rest mattered.
Questions owners ask
What does a website audit include?
Four layers. Indexability: whether robots.txt, the canonical tag and HTTPS let a crawler read the site. Speed: the three Core Web Vitals, measured against Google’s published thresholds of 2.5 seconds for LCP, 200 milliseconds for INP and 0.1 for CLS at the 75th percentile. Usability: the accessibility failures that stop a real visitor, most often low contrast text and unlabeled form inputs. And the contact path: what happens after someone submits the form. Automated reports cover the first two well and the fourth not at all.
Do Core Web Vitals affect Google rankings?
Yes, and less than most audit reports imply. Google’s page experience documentation states plainly that there is no single page experience signal, that Core Web Vitals are used by its ranking systems, and that good results in Core Web Vitals reports do not put your pages at the top of Search. The same page says chasing a perfect score for SEO reasons may not be the best use of your time.
What is the most common problem a website audit finds?
Low contrast text, by a wide margin. WebAIM’s February 2026 analysis of the top 1,000,000 home pages found it on 83.9% of them, ahead of missing image alt text at 53.1% and missing form input labels at 51%. Six issue types accounted for 96% of all errors detected, and they have been the same six for seven years.
Is a free website audit worth anything?
It is worth exactly what it measures, which is the machine-readable half. A scan can read your robots.txt, pull your Core Web Vitals from real Chrome traffic and flag unlabeled form inputs. It cannot tell you whether anyone answered the call that came from the page. That part you test by hand, by submitting your own form and timing the reply.
How often should a website be audited?
The machine-readable layer is worth rechecking when something changes: a redesign, a platform migration, a new booking widget. The contact path is worth testing more often than that, because it breaks silently. A form that stops delivering email looks identical to a quiet week.
Sources
- Google, web.dev: Web Vitals (Core Web Vitals thresholds; published May 4, 2020, last updated Oct 31, 2024) (2024)
- Google Search Central: Understanding page experience in Google Search results (2026)
- HTTP Archive, Web Almanac 2025 — Performance chapter (16,213,084 websites sourced from the Chrome UX Report, July 2025 crawl) (2025)
- HTTP Archive, Web Almanac 2025 — SEO chapter (same dataset) (2025)
- WebAIM, The WebAIM Million: accessibility evaluation of the top 1,000,000 home pages (February 2026) (2026)
- Google Search Central: Get your content in AI features (structured data guidance) (2026)
- SparkToro with Similarweb — In 2026, Less than One Third of Google Searches Still Send a Click (Similarweb desktop and mobile web panel, US, January to April 2026) (2026)
The first meeting starts with findings, not promises.The free Business Health Report reads your business and shows you what it found, in days.
Get Your Free Business Health Report