Guides: what matters on a website
Each guide takes one point and explains why it matters for your site, what the audit looks at and what we find on the sites we audit.
How these guides are written
Figures from our own audits
The figures come from the sites we have audited, with their period and their limits.
Sources you can open
Every rule we cite links to the official text: a law, a court ruling, an authority or a public register.
What the check does not tell you
Every guide ends with its limits: what an outside check cannot establish.
The guides, pillar by pillar
Security & encryption
HSTS: what it protects, and what can break
HSTS makes browsers use HTTPS from the very first request. What max-age, includeSubDomains and preload do, what breaks, and what the audit reads.
Read the guide →Secure cookie attributes: what each stops
Secure, HttpOnly, SameSite: what each cookie attribute prevents, which cookies really need them, and what the audit records on your website.
Read the guide →HTTP security headers: which ones matter
HSTS, CSP, X-Frame-Options: what each HTTP security header prevents, which ones come first, and what the audit records on your website.
Read the guide →Performance
Largest Contentful Paint: what delays it
LCP measures when a page's largest visible element appears. Google's thresholds, the four steps where time is lost, and what our audit measures.
Read the guide →Slow website: the causes in load order
A slow website rarely has a single cause. Here are the causes in the order a page runs into them, and what our audit measures at each step.
Read the guide →SEO & search visibility
Redirect chains: why one hop is enough
A 301 redirect does its job in one hop. Why redirect chains cost you, where they come from, and what the audit checks on your site.
Read the guide →SEO migration: before and after launch
A redesign can change every URL on your site. What to settle before launch, and what the audit remeasures once the new site is live.
Read the guide →Robots.txt: what it actually blocks
Robots.txt controls crawling, not indexing. The lines a crawler silently skips, the mistakes nobody sees, and what our audit checks in your file.
Read the guide →Structured data: which types still work
Organization, WebSite, BreadcrumbList, Article, Product: the structured data that still does something, and why it has to say what the page says.
Read the guide →Accessibility
RGAA: France's accessibility standard
The RGAA is France's official method for checking web accessibility. Who must apply it, how it maps to WCAG, and what a conformance audit involves.
Read the guide →WCAG 2.2 checklist: what blocks a visitor
WCAG 2.2 is the current W3C accessibility standard. Levels A and AA, the criteria that stop visitors, and what a checklist cannot tell you about your site.
Read the guide →Accessibility statement: who needs one
An accessibility statement says how far a website meets the accessibility standard. Who must publish one in Europe, what it contains, and what we check.
Read the guide →European Accessibility Act: who it covers
Since June 28, 2025, the EAA applies to websites that sell to consumers in the EU. Who is covered, which small businesses are exempt, and what to publish.
Read the guide →Compliance & privacy
Website imprint requirements in the EU
What an EU business website must publish about who runs it, what France adds, and the flaw few people check: a legal notice no page links to.
Read the guide →EU ecommerce legal requirements, explained
What an online store selling to EU consumers must display in 2026: identity, prices, guarantee, withdrawal, dispute body, order button and reviews.
Read the guide →Domain & network
DNSSEC: what it does and doesn't protect
DNSSEC signs your domain's DNS answers so they can't be forged. What it covers, what it doesn't encrypt, who turns it on, and what the audit checks.
Read the guide →DMARC: who can send email as your domain?
DMARC tells mailbox providers what to do with email that spoofs your domain. The three policies, the Gmail and Yahoo rules, and what the audit reads.
Read the guide →Domain expiration: what stops, and when
When a domain expires, your website and email stop the same day. Why renewals fail even on auto-renew, and what the audit reads from the registry.
Read the guide →Independence & resilience
CLOUD Act: is your website exposed?
The CLOUD Act reaches data held by US providers, even on servers in Europe. Which layers of your website it covers, and what the audit looks at.
Read the guide →What your website sends outside the EU
A visit can send your visitor's IP address outside the EU (fonts, analytics, videos). Why it counts as a transfer, and what the audit records.
Read the guide →EU web hosting: more than server location
A server in the EU is not enough: your host's jurisdiction, DNS, CDN and email matter too. The questions to ask before you choose.
Read the guide →Content & trust
llms.txt: what it does and who reads it
llms.txt summarizes a website for language models. Google Search said on June 15, 2026 that it ignores the file. Who reads it, and what matters more.
Read the guide →E-E-A-T: what Google means by it
Experience, expertise, authoritativeness, trust: what Google puts behind E-E-A-T, why it isn't a score, and what makes it visible on a page.
Read the guide →Untranslated content on multilingual sites
A heading added later, a theme message, a reused block: where untranslated content hides on a multilingual website, and what the audit compares.
Read the guide →Lorem ipsum left on a live website
Lorem ipsum is only the best-known kind. "[Insert name]" notes, XXXX dates, theme labels: the placeholder text that ships with a live website.
Read the guide →User experience & reliability
JavaScript console errors: what breaks
A JavaScript error on page load can disable a menu or a form, or change nothing for visitors. What makes the difference, and what the audit records.
Read the guide →Website images not showing: the causes
An image that's broken for every visitor comes from your site, not their browser. The causes, the files that break unseen, and what the audit records.
Read the guide →Situations and site types
Free website audit: what a scan can't see
What a free website audit measures well, what one automated pass can't see, and what our free audit covers: one page, one pillar.
Read the guide →Website audit tools: what each type checks
SEO, speed, security and accessibility tools: what each type of website audit tool measures well, what it skips, and when a human review changes the result.
Read the guide →Website audit cost: what sets the price
What drives the cost of a website audit: pages reviewed, languages, topics covered, human review, deliverables. And our public price list, plan by plan.
Read the guide →How to audit a website, pillar by pillar
What a website audit checks, in what order and why: which pages, the nine pillars, what needs a real browser, and how to read the score.
Read the guide →Ecommerce website audit: what it checks
Trackers before consent, required consumer information, security, domain, checkout: what our audit checks on an online store, and what it finds.
Read the guide →SEO audit vs website audit: the difference
An SEO audit checks that search engines read your pages. A website audit also covers security, legal, domain and accessibility. Which one you need.
Read the guide →Competitor website audit: what it compares
Audit a competitor's website on all 9 pillars, scored exactly like yours: what a passive audit compares, and what stays invisible from outside.
Read the guide →The audit's 9 pillars
Each guide belongs to one of them. Each chapter details what the audit checks on that pillar.
Security & encryption
Are your visitors' connections properly protected?
Performance
Does your site remain fast enough for its visitors?
SEO & search visibility
Can search engines understand your pages correctly?
Accessibility
Can people with different accessibility needs use your pages?
Compliance & privacy
Are the visible elements related to the obligations that apply to your site properly present and configured?
Domain & network
Are your domain and email infrastructure properly protected?
Independence & resilience
Who does your site depend on, and what happens if one of those dependencies becomes unavailable?
Content & trust
Is your content clear, credible and properly structured?
User experience & reliability
Do the pages and journeys that matter actually work?
