---
name: technical-seo-audit
description: Audit crawlability, indexability, security, URL structure, mobile experience, Core Web Vitals, and JavaScript rendering across 9 categories.
---

# Technical SEO Audit

## Use this when

technical SEO, crawl issues, robots.txt, Core Web Vitals, site speed, security headers.

## Process

Nine categories, each scored pass/warn/fail:

1. Crawlability: robots.txt exists and doesn't block important resources; a valid sitemap is discoverable; noindex tags are intentional, not accidental; important pages sit within 3 clicks of the homepage; distinguish AI-crawler training tokens (GPTBot, Google-Extended, ClaudeBot, Bytespider, CCBot, Applebot-Extended) from citability tokens (OAI-SearchBot, Claude-SearchBot) — blocking a training token doesn't affect classic Google Search or AI Overviews indexing, which run on plain Googlebot. Note Googlebot's roughly 2MB HTML fetch limit (uncompressed): bloated inline CSS/JS or oversized inline images can push structured data out of what gets indexed.
2. Indexability: canonical tags are self-referencing with no conflict against noindex; watch for near-duplicate and parameter-URL duplication; thin content below reasonable page-type minimums; pagination handled sanely; index bloat from unnecessary pages.
3. Security: HTTPS enforced with a valid certificate and no mixed content; CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy headers present; flag back-button hijacking (defeating the Back button via history.pushState/replaceState, including via a third-party ad script) as Critical — this became an enforced spam-policy violation in 2026.
4. URL structure: clean, hyphenated, descriptive URLs with no unnecessary query parameters; no redirect chains longer than one hop; under 100 characters; consistent trailing-slash convention.
5. Mobile & page experience: responsive design with a real viewport meta tag; touch targets at least 48x48px; 16px+ base font; the highest-value mobile check is actually content parity between mobile and desktop versions, not just responsive layout; flag intrusive interstitials and standalone consent-redirect pages.
6. Core Web Vitals: LCP target 2.5s or under, INP target 200ms or under (never reference FID, it was replaced by INP in 2024 and removed from CrUX/PSI), CLS target 0.1 or under, evaluated at the 75th percentile of real users. Use the core-web-vitals-data or search-console-performance playbook for real field data instead of lab estimates when available.
7. Structured data: detect and validate JSON-LD as the preferred format; hand off to the schema-markup playbook for full analysis.
8. JavaScript rendering: check whether critical content and canonical/meta-robots/structured-data appear in the initial server-rendered HTML rather than only after client-side JS runs — Google may use either the raw-HTML or JS-injected canonical if they conflict, and does not render JS at all on non-200 status codes. Prefer SSR/SSG (Next.js, Astro, SvelteKit) for public SEO content; treat client-side rendering as acceptable only for authenticated, non-indexed content.
9. IndexNow: check whether the site supports IndexNow for faster indexing on Bing, Yandex, and Naver (not Google).

Report a technical score with the 9-category breakdown, findings bucketed Critical/High/Medium/Low, and specific fixes. When PageSpeed/CrUX field data or Search Console indexation data is available (via the core-web-vitals-data or search-console-performance playbooks), use it to replace lab-only estimates and say so.
