Free Website Scan: What 85 Checks Across Speed, SEO, Security, Schema, AI Search and Conversion Find
Our free website scan reads the home page, a service page and a post and runs 85 checks in seven weighted areas, AI search the heaviest at 30 of the 100 points. Every check, the weighting and why, and how it compares to the five-check "free audits" that exist to capture an email.

The Zorva Labs website scan runs 85 free checks in seven areas that add up to 100 points: technical SEO 15, on-page SEO 20, AI search readiness 30, local and entity signals 10, speed and mobile 10, trust 10, conversion 5. AI search weighs the most because that is where people now get their answers, and an area's points drop faster than its checks, so a half-finished site scores well below half. It reads three pages rather than one, measures speed with Google PageSpeed (real-user Core Web Vitals first), and lists what to fix first by the points each fix is worth. No sign-up, no email gate, and every scan gets a public link.
Most "free SEO audits" exist to capture your email
Type "free SEO audit" into Google and you'll find dozens of tools that ask for your domain, your email, your company name, your phone number, and "what stage you're at" — and then return a five-check report scored so generously that almost any site gets a 72/100. The score is theatre. The email is the product.
We built our scan the opposite way. No sign-up, no email, no qualification quiz. Drop in a domain, get an honest 85-check report in about a minute, and walk away with a written fix list and a link you can send to whoever built the site. This post is the methodology — what the scan reads, what every area measures, how the score is weighted, and what a pass or a fail actually means. It was rewritten on 2026-09-26, when the scan went from 38 checks of the home page to reading three pages, and on 2026-09-27, when AI search went from 6 of the 100 points to 30, fifteen checks from the standard our own sites are built to went in, and the scoring got stricter.
Three pages, not one
A home page can be immaculate while every service page behind it is the same page with the town swapped. So the scan reads the home page, then picks a service page and a post from the sitemap and reads those too. That is where it sees whether the inner pages carry their own titles and descriptions, their own questions, an article's author — and whether they repeat each other's sentences, which is what Google's scaled-content rules are written against.
Seven areas, 100 points
The score is the sum of seven areas, each worth a set number of points. Inside an area a critical check counts three times, a major one twice, a minor one once, and a few are noted but never scored. The report shows each area's points out of its share, so the seven numbers add up to the score.
- Technical SEO & indexability — 15 points, 20 checks. Indexable by search engines, Canonical URL, Sitemap, Sitemap dates, robots.txt, Sitemap named in robots.txt, Missing pages return 404, Redirect chain, HTTPS certificate, HTTP redirects to HTTPS, www and apex agree, HSTS header, Mixed content, Security headers, Language declared, Lighthouse SEO score, Lighthouse best practices, Internal links resolve, Sitemap lists the live URLs, Structured data Google accepts.
- On-page SEO & content — 20 points, 17 checks. Page title, Meta description, Single H1, Title and H1 differ, Readable content in the HTML, Image alt text, Social share cards, Share image loads, Favicon, Pages read, Titles across the site, Descriptions across the site, Pages that repeat each other, Canonical and share card on every page, No stock phrases, No placeholder or template text, Pictures named and described for what they show.
- AI search / AEO / GEO readiness — 30 points, 14 checks. llms.txt, AI crawlers allowed, Readable without JavaScript, AI answers may quote the page, Questions answered on the page, FAQPage schema, FAQ questions visible on the page, FAQs on the inner pages, JSON-LD present and valid, Extractable structure, Freshness dates in schema, Speakable specification, Specifics an engine can cite, Schema on the inner pages.
- Local SEO & entity signals — 10 points, 6 checks. Business entity schema, Business schema completeness, Address and phone on the page, Linked to its profiles, Service area stated, Site name for Google.
- Performance & mobile — 10 points, 15 checks. Mobile PageSpeed score, Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Interaction to Next Paint (INP), What would speed it up most, Time to first byte, HTML weight, Compression, HTTP/2 or HTTP/3, Image hygiene, Mobile viewport, Pinch-to-zoom allowed, No fixed-width overflow, Lighthouse accessibility score, Readable and tappable on a phone.
- Trust / E-E-A-T / reputation — 10 points, 7 checks. Reviews on the page, Trust signals, Article schema on the post, A named person, About and privacy pages, No stock or AI-marked pictures, Not a stock template.
- Conversion & lead generation — 5 points, 6 checks. Tappable phone number, Contact form, Call to action in the first screen, Analytics installed, Chat or text option, Lead form wiring.
Why AI search is 30 of the 100 points
Fewer Google searches end on a website every year: 68% ended without a click in January–April 2026, up from 60% in 2024 (SparkToro). Where Google shows an AI Overview, the top-ranked page now gets 58% fewer clicks than it did before them (Ahrefs, 300,000 keywords, December 2025). The searches didn't go away; the answer moved onto the results page and into ChatGPT, Gemini and Perplexity. Those engines name the businesses whose sites they can read and quote, so whether a site is built for them now decides more of what it earns than any other single area.
Until 2026-09-27 the scan gave AI search three checks, 6 points of the 100, and a site with no llms.txt and no FAQ still scored in the high 80s. Now it is the heaviest area, and a site that has done none of the work earns about 5 of those 30 points.
Performance — Google's own measurement, real users first
Most free tools either skip performance or report their own crude timing. We call Google's PageSpeed Insights API for a mobile Lighthouse run of the home page and read four categories from the one call: performance, SEO, accessibility and best practices. For the Core Web Vitals we prefer what Google prefers — the real-user data from the Chrome User Experience Report, 28 days of it — and fall back to the lab run only when a page has too few visitors to have any. The lab number varies from run to run, so we run it twice and keep the better result, and we grade lab LCP more loosely than field LCP for that reason. PageSpeed's own top three opportunities, with their savings in seconds, appear as a check of their own, so the fix list is about your page rather than pages in general.
If PageSpeed does not answer within 45 seconds, the report still comes back, marked provisional: the performance checks are shown as not measured, they are left out of the score, and the leaderboard does not rank the scan until a later one measures them. The old scan quietly dropped them, which made a site look better the less could be measured.
Technical and on-page SEO — the estate's own rule
Titles pass at 30–60 characters and descriptions at 120–160 — the same rule the build system enforces on every site we ship. A page must be indexable: no noindex in the meta or the headers, and no wildcard Disallow in robots.txt. The canonical must be absolute, https, and point at the page itself; a canonical to another domain is a fail, because it tells Google to index that page instead. The sitemap is found the way a crawler finds it — through robots.txt first — and its dates are read: when every page carries the same date, it is a build stamp, and Google learns to ignore it. A made-up URL has to return a real 404. The share image is fetched, not just found in a tag. And the HTML has to carry readable words: a page drawn entirely by JavaScript looks empty to a crawler.
Security and mobile — the certificate included
The viewport, pinch-to-zoom, fixed widths that overflow a phone, HSTS, the http redirect, mixed content (counted only on real resources — a plain link to an http:// site is not mixed content, whatever other tools say), the four baseline headers, and Lighthouse's accessibility and best-practices scores. The certificate is read over TLS on the host and on its www or apex twin, with the days to expiry: a site whose www version shows a browser warning fails here even though the apex is fine, because that is what a visitor who types www sees.
AI search — can the engines read it, and is it built to be quoted?
Two halves. First, whether the answer engines can read the site at all: robots.txt read with a real parser, so GPTBot, OAI-SearchBot, ClaudeBot, PerplexityBot, Google-Extended, Bingbot, Applebot and the rest are checked against the group that actually governs them; the home page fetched as the crawlers themselves, because a CDN's bot rules can refuse one that robots.txt lets in; the words in the HTML the server sends, because ChatGPT's, Claude's and Perplexity's crawlers run no JavaScript; and nothing that stops an engine quoting the page (nosnippet keeps a page out of Google's AI Overviews, and Bing leaves a noarchive page out of Copilot's answers).
Then whether the site is built to be quoted: an llms.txt that is really a text file; questions asked and answered on the pages we read, whatever the markup — the shape an AI answer is lifted from; FAQPage schema on the home page and the inner pages, with its questions on the page, because Google drops markup for content it cannot see; JSON-LD that parses; headed sections and lists; a freshness date. Nearly every site passes the first half without trying, so it counts for little on its own; the second half carries the weight. And when an engine is refused, or the page is blank without JavaScript, the whole area counts 8 of its 30 points at most — nothing else in it reaches an engine that can't read the site.
The standard our own sites are built to
Fifteen of the checks are the rules a site of ours has to pass before it launches, read here from outside so any site can be held to them. The links on the home page and in llms.txt have to lead somewhere. The sitemap has to list the live addresses, and every inner page we read needs its own canonical, share card and schema. The structured data can't carry anything Google rejects, like a rating on a Service or a Product with no price. The copy is read for stock phrases (look no further
, we pride ourselves
), for text a template left behind (lorem ipsum
, Elementor's Add Your Heading Text Here
), and for the specifics an engine can quote: prices, timelines, counts, the names of places and products. A page with none reads the same as a competitor's.
The pictures are read by name, by alt text and by the credits inside the files. A photo bought from iStock, Getty or Shutterstock, a download still named ChatGPT Image
and a date, alt text that is the prompt a picture was made from: each is flagged, and one in a section that shows the business's work fails, because it stands in for work nobody can check. The builder or theme is named (Wix, Squarespace, GoDaddy, Duda, WordPress on Astra, Divi or Avada), and whatever the template left showing, such as the theme's own credit in the footer, is a failure. So is a quote form that only opens the visitor's email app.
Local SEO and entity signals — does anyone know who you are?
An Organization or LocalBusiness node and how complete it is (name, phone, address, logo, area served, hours); the address and phone on the page as text, with the phone matched against the schema's; sameAs links that tie the site to the Google Business Profile, Facebook, Yelp and the rest, so the engines know they are one business; and a stated service area.
Trust, E-E-A-T and reputation
Reviews or a rating on the page, trust language — licensed, insured, a warranty, years in business, a credential — Article schema with an author on the post we read, an About page and a privacy policy, pictures that aren't stock or AI-made, and a site that isn't a stock template. A named person is noted, never scored, on a home page.
Conversion and lead generation
For a service business the site's job is the call, so the scan grades it: a tappable phone number (a number shown as text but not a tel: link is a warning), a form on the home page, a call to action in the first screen, analytics that count what happens, and a chat or text option (noted, never scored).
How we score
area rate = sum(weight × value) / sum(weight), over the area's checks
area points = the area's points × rate^1.5 (15, 20, 30, 10, 10, 10, 5)
score = the sum of the seven areas' points, held at 40 when the home page is noindex
value: pass 1 · warn 0.25 · fail 0 · info excluded
weight: 3 critical · 2 major · 1 minor · 0 shown but never scored
The curve is deliberate. Search and AI answers pay the sites that finish the work, so an area's points drop faster than its checks: 90% done earns 85% of the points, 70% earns 59%, half earns 35%. A warning is something to fix, so it counts a quarter of a pass. Checks that only look for faults, like placeholder text or a broken link, cost points when they find one and add nothing when they don't. A failed gate caps its area: an answer engine refused, or a page drawn by JavaScript, holds AI search to 8 of its 30 points, and a home page marked noindex holds the whole score to 40. Every check that failed or warned carries the points fixing it would add, and "What to fix first" is in that order. A rescan keeps the score it replaced only when both were scored the same way, so the leaderboard shows how far a site moved rather than how the method changed.
How we compare to the "free audit" tools that ask for your email
| Capability | Zorva website scan | Typical "free SEO audit" |
|---|---|---|
| Checks | 85, weighted | 5–12 |
| Pages read | Home, a service page, a post | Home page |
| Email gate | None | Required |
| Core Web Vitals | Google's own, real users first | Rarely |
| Certificate | Read on www and apex, with expiry | "HTTPS: yes" |
| AI search | 30 of the 100 points | 0 |
| Conversion | Its own area | 0 |
| Copy, photos and theme | Stock phrases, stock and AI photos, template leftovers | Never read |
| Fix recommendations | On every failing check | "Upgrade to see" |
| Time | About a minute | 30+ seconds, often gated |
| Cost | Free | "Free trial" |
FAQ
Does it work on any site?
Any public website. We fetch the pages the way a browser would. Sites behind aggressive bot protection sometimes answer 403 — the report names the protection and says so, since that is a deliberate rule rather than an SEO fault. Deploy previews and staging hosts are scanned but never published. Private networks and bare IP addresses are refused.
Why 85 checks instead of 100?
We test what moves rankings, AI citations and calls in 2026, and we weight it. Most "100-check audits" pad the list with checks that have not mattered since 2018 (meta keywords, header tag length, h2-to-paragraph ratio) and count them all the same.
Why no email gate?
Email gates exist to feed sales pipelines. If you like what the report says, the optional form under it puts a person on it — Michael reads the report and writes back with the first three things to fix. If you don't, the report is yours either way.
How often can I rescan?
One scan per domain every 30 days; a repeat inside the month shows the stored report and the date the next one opens. Leave your details under the result if you have fixed things and want a fresh read sooner.
Is my scan private?
Every scan of a live public website publishes at its own link and joins the live leaderboard the moment it completes, with the change since its last scan. To remove a domain, email zorvalabs@gmail.com.
Run yours — no signup, no email gate
Every tool at zorvalabs.com/tools is free, instant, and locks nothing behind an email form. You'll see the same numbers we see when we audit a paying client's site — same checks, same thresholds, same fix recommendations. If you want us to actually ship the fixes, request a quote — priced to your project, written proposal in one business day. If you just want the report and a checklist, take it and run.