Fetch the page safely
Public HTTP and HTTPS only. The scanner resolves the host, rejects private and reserved networks, pins the resolved address, and re-validates every redirect hop rather than handing the chain to cURL.
Versioned PHP rules run against observable evidence from your page. No language model decides the number, and nothing about the score changes between runs unless your site does. Method OR-AUDIT-3.0.0.
Four conditions stop a page being indexed or cited at all. They cap the report rather than subtract from it.
Reports show the measured score alongside the capped one, so a site sitting at 88 underneath a single bad directive is told exactly that.
A generative answer can sound confident and still be wrong. Every point is calculated before any narrative summary is written, so the words can never contradict the evidence.
Public HTTP and HTTPS only. The scanner resolves the host, rejects private and reserved networks, pins the resolved address, and re-validates every redirect hop rather than handing the chain to cURL.
HTML, response headers, robots.txt, sitemap location, crawler directives, structured data, headings, links, images and a small internal-page sample.
noindex, Googlebot disallowed, two or more AI search crawlers disallowed, or no HTTPS. Passing a gate earns no points; failing one caps the report, because the remaining findings are moot.
Checks ask how well something is done, not whether a tag exists. A stock CMS fills in titles, descriptions, canonicals, sitemaps and schema automatically, so scoring their presence would hand every competent site a high mark for no work.
The evidence engine ranks the checks that already failed. It cannot add points, alter evidence or invent performance data.
These are not deductions weighed against everything else. Each one prevents the page being found, indexed or cited, so no amount of good work elsewhere compensates.
A robots meta tag, googlebot meta tag or X-Robots-Tag header excludes the page from search indexes entirely.
robots.txt blocks Googlebot from the audited path, so the page cannot reach Google Search or AI Overviews.
The crawlers that build the indexes AI assistants cite from cannot reach the page, however good the content is.
The page resolves over plain HTTP, failing the minimum technical requirement for modern search eligibility.
Title quality and content substance are core. A weighted average would otherwise hide a 40-word page behind passing boilerplate checks.
A generic title on a page with no substantive content cannot honestly be described as anything but at risk.
Why gates earn no points when they pass. An earlier version of this audit awarded points for simply not being broken, which pushed the lowest possible score to 56 and left every real site clustered in the eighties. Gates now sit outside the total entirely: being adequate earns nothing, and being broken is decisive.
Weights are fixed in code and published here. Where a check is worth more when it fails than when it passes, both numbers are shown: being broken should hurt more than being adequate helps.
Pass earns full weight, a warning earns half, a failure earns zero. Category and overall scores are normalised to 100. Every check in a report carries an evidence ID you can match against this table.
Counting these would inflate findings and penalise decisions that are not defects.
Blocking GPTBot, ClaudeBot, Google-Extended, Applebot-Extended, CCBot, Bytespider or Meta-ExternalAgent is a content-licensing decision. It carries no search-visibility penalty, so it carries no score penalty.
No major AI search product currently requires one. Reporting its absence as a finding would manufacture urgency around an emerging convention.
If a page renders client-side, its content cannot be read from the HTML response. That check is marked not scored and removed from the total rather than quietly awarded half credit.
If a firewall refuses the scanner, the audit returns a clearly labelled partial report covering crawl directives only, instead of guessing at on-page findings.
The public audit has no permission to see your analytics or webmaster accounts, and it reads one page rather than crawling a site. These limits are listed so a score is read for what it is.
Every completed scan produces a SHA-256 fingerprint from the method version, audited URL, score and full evidence ledger. It is not a signature and does not prove authorship. It is a compact identifier that changes whenever the scored evidence changes.
The method version is printed on every report, so a change in scoring can always be told apart from a change to your website. Reports produced under an older method keep their original version string.
The complete evidence ledger is shown on screen before you give an email address for the PDF, so nothing in the scoring is held back behind the form.
Platform documentation defines which crawlers matter and what they do. Everything beyond that is stated as a limitation rather than converted into a guarantee.
Every scored check, its status, its points and the evidence behind it are shown before you download anything.