How a score is built

Versioned PHP rules run against observable evidence from your page. No language model decides the number, and nothing about the score changes between runs unless your site does. Method OR-AUDIT-3.0.0.

Ceilings, not deductions

Four conditions stop a page being indexed or cited at all. They cap the report rather than subtract from it.

The scoring pipeline

A generative answer can sound confident and still be wrong. Every point is calculated before any narrative summary is written, so the words can never contradict the evidence.

01

Fetch the page safely

Public HTTP and HTTPS only. The scanner resolves the host, rejects private and reserved networks, pins the resolved address, and re-validates every redirect hop rather than handing the chain to cURL.

02

Collect observable evidence

HTML, response headers, robots.txt, sitemap location, crawler directives, structured data, headings, links, images and a small internal-page sample.

03

Apply the gates

noindex, Googlebot disallowed, two or more AI search crawlers disallowed, or no HTTPS. Passing a gate earns no points; failing one caps the report, because the remaining findings are moot.

04

Grade on quality, then weight

Checks ask how well something is done, not whether a tag exists. A stock CMS fills in titles, descriptions, canonicals, sitemaps and schema automatically, so scoring their presence would hand every competent site a high mark for no work.

05

Summarise the same evidence

The evidence engine ranks the checks that already failed. It cannot add points, alter evidence or invent performance data.

Terminal conditions

What caps a report

These are not deductions weighed against everything else. Each one prevents the page being found, indexed or cited, so no amount of good work elsewhere compensates.

Caps at 39

noindex directive

A robots meta tag, googlebot meta tag or X-Robots-Tag header excludes the page from search indexes entirely.

Caps at 39

Googlebot disallowed

robots.txt blocks Googlebot from the audited path, so the page cannot reach Google Search or AI Overviews.

Caps at 39

Two or more AI search crawlers disallowed

The crawlers that build the indexes AI assistants cite from cannot reach the page, however good the content is.

Caps at 39

Not served over HTTPS

The page resolves over plain HTTP, failing the minimum technical requirement for modern search eligibility.

Caps at 69

One core dimension fails

Title quality and content substance are core. A weighted average would otherwise hide a 40-word page behind passing boilerplate checks.

Caps at 54

Both core dimensions fail

A generic title on a page with no substantive content cannot honestly be described as anything but at risk.

Why gates earn no points when they pass. An earlier version of this audit awarded points for simply not being broken, which pushed the lowest possible score to 56 and left every real site clustered in the eighties. Gates now sit outside the total entirely: being adequate earns nothing, and being broken is decisive.

Every check and what it is worth

Weights are fixed in code and published here. Where a check is worth more when it fails than when it passes, both numbers are shown: being broken should hurt more than being adequate helps.

Answer and AI search readiness
AI search crawler accessGooglebot, Bingbot, OAI-SearchBot, Claude-SearchBot, PerplexityBot, Applebot
18
Structured data completenessDeclared types carry their required properties
10
Snippet eligibilityNo nosnippet or max-snippet:0 restriction
6
User-triggered AI fetchChatGPT-User, Claude-User, Perplexity-User
4
Content and on-page
Content substancecoreSubstantial paragraphs, sentence structure, text-to-HTML ratio
18
Title qualitycoreDescriptive rather than generic boilerplate, correctly sized
14
Internal link qualityShare of anchors carrying real topical meaning
9
Heading hierarchyOne H1, no skipped levels, no empty heading tags
8
Meta description qualityA distinct sentence, not a copy of the title
6
Descriptive image alt textInformative images described, decorative ones correctly empty
6
Rendering and delivery
Server-rendered contentPrimary content present in the initial HTML response
14
Render-blocking deliveryBlocking scripts and stylesheets in head, document weight
10
Image deliveryDimensions set, modern formats, lazy loading
8
Technical foundations
Mobile viewportWorth 8 when missing, 3 when present
8
Canonical correctnessSelf-referencing and matching the live URL
7
XML sitemapWorth 7 when absent, 3 when confirmed
7
Redirect efficiencyNumber of hops before the page resolves
5
Transport securityHSTS present with an adequate max-age
4
robots.txtWorth 4 when absent, 2 when retrieved
4
Language declarationA lang attribute on the html element
2
Gates
noindex directiveScored as a gate: zero points when passing, caps the report when failing
20
Googlebot disallowedScored as a gate: zero points when passing, caps the report when failing
20
Not served over HTTPSScored as a gate: zero points when passing, caps the report when failing
12

Pass earns full weight, a warning earns half, a failure earns zero. Category and overall scores are normalised to 100. Every check in a report carries an evidence ID you can match against this table.

Deliberately excluded

What the audit refuses to score

Counting these would inflate findings and penalise decisions that are not defects.

Reported, never scored

Training crawler policy

Blocking GPTBot, ClaudeBot, Google-Extended, Applebot-Extended, CCBot, Bytespider or Meta-ExternalAgent is a content-licensing decision. It carries no search-visibility penalty, so it carries no score penalty.

Reported, never scored

llms.txt

No major AI search product currently requires one. Reporting its absence as a finding would manufacture urgency around an emerging convention.

Removed from the denominator

Checks that cannot be measured

If a page renders client-side, its content cannot be read from the HTML response. That check is marked not scored and removed from the total rather than quietly awarded half credit.

Partial report

Sites behind bot protection

If a firewall refuses the scanner, the audit returns a clearly labelled partial report covering crawl directives only, instead of guessing at on-page findings.

What this scan cannot know

The public audit has no permission to see your analytics or webmaster accounts, and it reads one page rather than crawling a site. These limits are listed so a score is read for what it is.

  • No access to Search Console, GA4 or Bing Webmaster Tools, so no clicks, impressions or conversions are claimed.
  • No backlink authority, keyword positions, competitor share or live AI citation counts.
  • Server fetch time is a delivery proxy, not field Core Web Vitals.
  • JavaScript is not executed. Client-rendered content is detected and flagged, not read.
  • One page plus a small internal sample. Template-wide issues need a full-site crawl.
  • Thresholds and weights are informed editorial judgment, not values derived from ranking data.
  • AI answers are probabilistic. Crawler access and readiness cannot guarantee a future citation.

Checking a report against this page

Every completed scan produces a SHA-256 fingerprint from the method version, audited URL, score and full evidence ledger. It is not a signature and does not prove authorship. It is a compact identifier that changes whenever the scored evidence changes.

The method version is printed on every report, so a change in scoring can always be told apart from a change to your website. Reports produced under an older method keep their original version string.

The complete evidence ledger is shown on screen before you give an email address for the PDF, so nothing in the scoring is held back behind the form.

Run the audit, then check the ledger

Every scored check, its status, its points and the evidence behind it are shown before you download anything.

Run AI Search Audit