GEO audit example — a real AI visibility report
A real GEO and SEO audit of our own site, with the scores, answer-engine citations and fixes exactly as the product produces them. Switch plans to see what each one includes.
KwKeywords & contentPrimary keyphrase, density & placement, and 12-month search demandWarn · 65›
How this score is made65 of 100 points, 1 of 3 checks lost something
- Keyphrase placement40 / 40primary phrase "apple airpods pro" appears in title, H1, URL slug, meta descriptionThe four places a search engine and an extractive answer engine both look for what a page is about. Weighted by where each carries most signal (title and H1 above slug above meta description), and the slug leaves the denominator on a root URL, which has no slug to hold a phrase.
- Keyphrase density25 / 25the primary phrase sits inside the target density bandOur judgement: a 40–300% share of words is the long-standing convention for "present without stuffing". Google publishes no density target, but keyword stuffing IS a documented spam policy, so the band is defensible in both directions.
- Search position0 / 35this page does not appear in the first 10 organic results for the phrase it targetsA measured zero, not an absence: the search ran and the page was not there. Ranking nowhere for your own declared phrase is the single most consequential on-page finding, which is why the module cannot reach a passing score without it.
This page does not rank for “apple airpods pro”, the phrase it targets. That is why this card cannot exceed 65: the position is worth 35 of 100 and it earned none of it. The ceiling is the finding — placement and density can both be perfect and the number will still sit here, because the page is doing the on-page work and not yet winning the search.
| # | Phrase | Count | Density % of words | Placement | Volume | Ad competition not SEO difficulty |
|---|---|---|---|---|---|---|
| 1 | apple airpods pro | 9 | THUM | — | — | |
| 2 | dušenje hrupa | 10 | THUM | — | — | |
| 3 | usb-c | 17 | THUM | — | — | |
| 4 | vrhunsko dušenje hrupa | 0 | THUM | — | — | |
| 5 | prostorski zvok | 9 | THUM | — | — | |
| 6 | kompaktnih slušalkah | 0 | THUM | — | — | |
| 7 | aktivno dušenje hrupa | 7 | THUM | — | — | |
| 8 | odpravljanjem šuma | 5 | THUM | — | — | |
| 9 | usb-c vrhunsko dušenje hrupa | 0 | THUM | — | — | |
| 10 | brezžične slušalke | 2 | THUM | — | — |
MtMeta & tagsTitle, description, headings and social tagsPass · 100›
How this score is made6 of 6 checks clean — nothing wrong here
- Title length25 / 25title is 41 charactersGoogle truncates titles past roughly 60 characters in the result and one under 30 wastes the strongest on-page field. Binary — inside the band or not.
- Meta description25 / 25description is 144 charactersGoogle rewrites descriptions outside roughly 110–155 characters, so a non-conforming one forfeits control of the snippet rather than failing outright. Weighted level with the title because losing the snippet costs clicks even when ranking is unaffected.
- Canonical URL15 / 15a canonical URL is declaredGoogle Search Central: a canonical consolidates duplicate URLs (tracking parameters, print views, trailing-slash variants) onto one indexed address. Binary.
- Open Graph tags15 / 15Open Graph tags are presentOpen Graph protocol — what every social platform reads when the page is shared. Our judgement on the weight: it costs nothing in search and everything in how a share looks.
- Twitter card tags10 / 10Twitter card tags are presentOur judgement, weighted below Open Graph because X falls back to the OG tags, so their absence is rarely visible to a reader.
- Viewport meta10 / 10a viewport meta tag is setRequired for mobile rendering, and Google indexes mobile-first. Low weight only because it is nearly universal; when it IS missing the page is broken on a phone, which the Mobile card grades directly.
| Check | Result | Status |
|---|---|---|
| Title length | 41 chars | pass |
| Meta description length | 144 chars | pass |
| H1 headings | 1 | pass |
| Canonical URL | present | pass |
| Open Graph tags | present | pass |
| Open Graph image | present | pass |
| Twitter / X card | present | pass |
| Favicon | present | pass |
| Viewport (mobile) | present | pass |
| Indexable (no noindex) | indexable | pass |
⚡Performance & Core Web VitalsMobile and desktop, scored separatelyWarn · 75›
How this score is made75 of 100 points, 1 of 1 checks lost something
- Lighthouse performance75 / 100Lighthouse scores this page 75 of 100 on lab dataGoogle's own published composite of First Contentful Paint, Speed Index, Largest Contentful Paint, Total Blocking Time and Cumulative Layout Shift, at Google's weights. Taken whole rather than re-derived from the vitals we hold — a second computation would disagree with the number Lighthouse published, and this card exists to report Google's verdict.
This card shows one number deliberately. The Lighthouse performance score is already Google's own weighted composite of five metrics, at Google's weights — splitting it into per-metric rows would look like more working while producing a figure that disagrees with the one Google published. One measurement reported whole beats three that imitate arithmetic.
The individual vitals sit below it as facts rather than as a second score, and the mobile run is the half that feeds your Technical pillar, because Google indexes mobile-first.
How the mobile score is made90 of 100 points, 1 of 3 checks lost something
- Viewport meta tag25 / 25a viewport meta tag is declaredMere PRESENCE of the tag — the weakest of the three signals, which is why the Lighthouse judgement below is weighted higher: a viewport tag can be declared and still be wrong.
- Mobile-optimised viewport35 / 35Lighthouse judges the viewport genuinely mobile-optimisedLighthouse's `viewport-insight` audit — its judgement that the tag is configured for a phone rather than merely present. Weighted above the tag itself because it is the one that can disagree with it.
- Mobile Core Web Vitals30 / 40mobile Core Web Vitals score 75 of 100The three Core Web Vitals as measured on the MOBILE run (web.dev thresholds), and the heaviest weight here because it is the only continuous, richly-informative signal of the three — the other two are booleans about configuration.
| Top opportunity (mobile) | Est. saving |
|---|---|
| Reduce unused JavaScript | 1.1 s |
| Reduce unused CSS | 0.5 s |
| Top opportunity (desktop) | Est. saving |
|---|---|
| Reduce unused JavaScript | 0.2 s |
ImImagesAlt text, formats and dimensionsPass · 100›
How this score is made4 of 4 checks clean — nothing wrong here
- Alt text40 / 40every image has alt textWCAG 2.2 SC 1.1.1 (Non-text Content) requires a text alternative, and Google Images uses alt text to understand a picture. Saturates at ALL images missing it — the worst case is a page no screen reader or image index can read.
- Dimensions declared25 / 25every image declares width and heightUndeclared dimensions are a direct cause of layout shift, and CLS is a Core Web Vital with a 0.1 'good' threshold (web.dev/cls). Weighted below alt text because a single image rarely dominates CLS.
- Modern formats25 / 25all images use a next-gen formatOur judgement, not a standard: Lighthouse flags 'Serve images in next-gen formats' as an opportunity rather than an audit failure, so it costs page weight rather than correctness.
- Sized for display10 / 10no image is larger than its display boxOur judgement, weighted lowest: oversized images waste bandwidth but render correctly, and on a fast connection the reader never notices.
InInternal linksLink graph, depth and broken linksPass · 100 ≤ 2 of 3›
How this score is made2 of 2 checks clean — nothing wrong here
- Broken internal links45 / 45no broken links among the 30 checkedGoogle's own guidance treats broken internal links as wasted crawl budget and a dead end for readers. Saturates at 10% of the sample: past that the navigation is broken as a whole rather than in places.
- Orphan pagesnot measuredthe site-wide link graph was not built on this audit
- Click depth25 / 25no page sits deeper than 3 clicksThree clicks is our judgement, and a long-standing SEO convention rather than a Google rule: depth correlates with crawl frequency because each level dilutes internal links. Saturates at a quarter of the links being deep.
This is an upper bound: the checks above are all we could take, and the ones we could not can only lower it. It is the ceiling for this page, not its score.
The ≤ on this score means orphan pages was not measured. Building the site-wide link graph needs a fuller crawl than this audit took. That check left the denominator rather than passing by default, so the number above is a CEILING — measuring it could only have lowered it, never raised it.
ExExternal linksOutbound links, rel attributes and safetyPass · 100 ≤ 2 of 3›
How this score is made2 of 2 checks clean — nothing wrong here
- Broken outbound links45 / 45no broken links among the 9 checkedA dead outbound link is a broken promise to the reader and a stale-content signal. Saturates at 15% of the sample — higher than the internal threshold because link rot on other people's sites is partly outside the owner's control.
- Safe new-tab links30 / 30every new-tab link sets rel=noopenertarget=_blank without rel=noopener gives the opened page access to window.opener — the tab-nabbing hole (OWASP; MDN rel=noopener). A security defect, so it saturates at ALL such links rather than a percentage.
- Outbound authoritynot measuredno backlink provider ran on this audit, so link authority was never fetched
This is an upper bound: the checks above are all we could take, and the ones we could not can only lower it. It is the ceiling for this page, not its score.
The ≤ means outbound authority is missing from this score: no backlink provider ran on this audit, so we never fetched the authority of the domains you link to. That check left the denominator rather than passing by default, and it could only have lowered the number — this is the ceiling, not the result.
BlBacklinks & authorityReferring domains and off-page authority — a trust signal search + AI weigh heavilylocked›
CrCrawlability & indexationrobots, sitemap, status codes and AI crawlersPass · 100›
How this score is made7 of 7 checks clean — nothing wrong here
- robots.txt12 / 12robots.txt is servedGoogle's crawler requests /robots.txt on every visit; its absence is not an error but it forfeits all crawl direction. Binary — the file is present or it is not.
- XML sitemap15 / 15sitemap found, listing 68 URLsGoogle Search Central lists a sitemap as the primary discovery aid for pages that are weakly linked internally. Binary, and weighted above robots.txt because it adds discovery rather than only restricting it.
- Redirecting pages11 / 11no redirects among the pages crawledA sitemap-listed URL that redirects spends crawl budget to reach a page the sitemap could have named directly. Saturates at 20% — our judgement, the most forgiving threshold here because a redirect still serves the reader correctly.
- noindex on listed URLs10 / 10no crawled page is marked noindexA sitemap asks Google to index a URL the page itself refuses — a direct self-contradiction, and Search Central calls out the mismatch explicitly. Saturates at 5%: our judgement, strict because the site is arguing with itself.
- Pages returning 4xx20 / 20no 4xx responses among the pages crawledA 404 on a sitemap-listed URL is a page the site claims exists and does not. Saturates at 10% of pages crawled — our judgement, set low because a sitemap should not list dead URLs at all.
- Pages returning 5xx20 / 20no server errors among the pages crawledA 5xx is a fault on our side of the wire, and Google backs off crawling a host that returns them. Saturates at 2% — far stricter than 4xx, because any server error is an outage symptom.
- Canonical consistency12 / 12no canonical conflicts among the pages crawledA canonical pointing somewhere unexpected tells Google to index a different URL than the one it fetched (Search Central, consolidate duplicate URLs). Saturates at 15% — our judgement.
SeSecurity & TLSHTTPS, TLS, mixed content and every key security header — explained, pass or failWarn · 71›
How this score is made71 of 100 points, 2 of 5 checks lost something
- HTTPS45 / 45the page is served over HTTPSChrome marks plain HTTP as Not Secure and Google has confirmed HTTPS as a ranking signal. Binary, and the largest weight here because every other transport signal is meaningless without it.
- No mixed content15 / 15no insecure subresourcesBrowsers block active mixed content outright and flag passive mixed content, so a single insecure subresource can break the page or strip the padlock. Binary — the page is clean or it is not.
- HSTS0 / 12no Strict-Transport-Security headerHSTS closes the first-request downgrade window that HTTPS alone leaves open (OWASP Secure Headers). Weighted below mixed content because it hardens an already-working HTTPS setup rather than fixing a visible fault.
- TLS 1.38 / 8the host negotiates TLS 1.3TLS 1.3 (RFC 8446) removes the legacy cipher suites and cuts a round trip from the handshake. Our judgement, weighted low: TLS 1.2 correctly configured is not a vulnerability, so this is hygiene rather than a defect.
- Security headers3 / 201 of 6 recommended security headers are setThe six are the OWASP Secure Headers baseline (CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-Frame-Options, COOP). Linear rather than saturating: each header closes a distinct class, so the fifth is worth as much as the first.
Only 1 of the six recommended security headers are set. Each closes a distinct class of attack rather than adding to one score, which is why they are counted linearly — the fifth is worth as much as the first, and they are usually a few lines of server configuration.
| Check | Status | What it does |
|---|---|---|
| HTTPS | pass | Encrypts every request. A ranking and trust baseline — plain HTTP is flagged by browsers. |
| Mixed content | pass | Sub-resources (images/scripts) loaded over http on an https page — browsers block or warn. |
| TLS 1.3 | pass | The current TLS version — faster handshakes and modern ciphers. |
| HTTP protocol | HTTP/2 | HTTP/2+ multiplexes requests — older HTTP/1.1 slows many-asset pages. |
| Strict-Transport-Security (HSTS) | FAIL | Tells browsers to ALWAYS use https for this site — defeats downgrade attacks. |
| Content-Security-Policy (CSP) | pass | Whitelists where scripts/styles may load from — the main defence against XSS. |
| X-Content-Type-Options | FAIL | “nosniff” stops browsers guessing file types — blocks a class of injection tricks. |
| X-Frame-Options / frame-ancestors | FAIL | Stops other sites embedding yours in an iframe — prevents clickjacking. |
| Referrer-Policy | FAIL | Controls how much URL information leaks to other sites when visitors click away. |
| Permissions-Policy | FAIL | Switches off browser features you don't use (camera, mic, geolocation) for embedded content. |
SdStructured dataschema.org / JSON-LD for rich results & AIPass · 100›
How this score is made3 of 3 checks clean — nothing wrong here
- Organization or Person schema25 / 25the publisher is identified in schemaschema.org/Organization is how a site states who publishes it — the entity Google and the answer engines resolve a brand to. Binary.
- Content schema25 / 25the page's content type is declared in schemaGoogle's rich-result eligibility is per TYPE (Article, Product, FAQPage): without one the page can be indexed but cannot win an enhanced result. Binary.
- Valid schema blocks50 / 50every schema block validatesGoogle's Rich Results Test rejects a block missing its required properties outright, so an invalid block buys nothing while looking like it does. Saturating: one malformed block is a different problem from ten, and past a few the markup is simply unreliable. The heaviest weight because a broken block is worse than an absent one — it claims a capability the page does not have.
TcTechnical SEO checksCanonical, indexing rules, render-blocking resources, structured-data @id integrity, pagination and URL formnot scored›
These checks did not run on this audit — re-run it to capture them.
| No duplicate titles | clean |
| No duplicate meta descriptions | clean |
| No redirect loops | clean |
| hreflang alternates point back | clean |
| hreflang alternates resolve directly | clean |
| The canonical URL serves | clean |
| The canonical stays on this domain | clean |
| Missing pages return 404, not 200 | clean |
⚙Tech stackCMS, theme, framework, server, CDN, libraries and plugins — with versions where the markup exposes themnot scored›
None of this is graded — which CMS or server you run is a fact about how the site is built, not a measure of how well it is built. It is here because knowing the stack is what makes the rest of this report actionable: the fixes elsewhere are written for the platform we detected.
A CDN was detected (LiteSpeed). It serves your files from a location near each visitor, which is mostly a latency win for an audience spread across regions.
We report the libraries the markup exposes. We do NOT check their versions against known vulnerabilities, so treat this as an inventory rather than a security review.
| Component | Detected |
|---|---|
| CMS / platform | wordpress 7.0.2 |
| Theme | kadence |
| Framework | — |
| Server | LiteSpeed |
| CDN | LiteSpeed |
| Libraries | jQuery 0.2.3 |
| Plugins | 2 detected |
What this tells you. None of it is graded — which CMS or server you run is a fact about how the site is built, not a measure of how well it is built. It is here because knowing the stack is what makes the rest of this report actionable: the fixes elsewhere are written for the platform we detected — yours is wordpress, so you get its step-by-step paths.
- CDN — serves your files from a location near each visitor. We detected LiteSpeed.
- Server — reported as LiteSpeed. Useful mainly when a fix elsewhere needs a config file, since the file and its syntax depend on it.
- Framework & libraries — what the page loads to run. We report what the markup exposes; we do not check versions against known vulnerabilities, so treat this as an inventory rather than a security review.
- Plugins — 2 detected. Each one is code you did not write running on every page, so the inventory is worth reviewing periodically for things you no longer use.
◉Analytics & trackersAnalytics, ad pixels, tag managers and consentPass · 100›
How this score is made4 of 4 checks clean — nothing wrong here
- Analytics installed40 / 40a web analytics tool is installedOur judgement, and the largest weight here: without analytics none of the other fixes in this report can be measured for effect. A measured zero — we read the page and found none — so it is a real fail with a finding, not an absence.
- Consent before non-essential tags30 / 30a consent platform was detected alongside the ad and social pixelsGDPR/ePrivacy require prior consent for non-essential tracking in the EU, and Google Consent Mode v2 is the mechanism Google itself requires for ad tags. Binary, and weighted second because it is a legal exposure rather than a measurement gap.
- Tag manager wiring15 / 15no tag-manager misconfiguration was detectedA container with no visible GA4 tag may be collecting nothing at all, which is worse than no analytics because it looks installed. GA4 and GTM together is the recommended setup and earns full marks here.
- No duplicate or retired tools15 / 15no duplicate or retired analytics toolsOur judgement, weighted lowest and saturating at both issues present: overlapping trackers fragment data and add page weight, but they do not stop measurement the way the three faults above do.
We found: Google Analytics 4 measurement ID G-EZXJNMPTSX appears 8 times in the page source. A tag loaded twice reports every event twice — double the pageviews, double the conversions, and a bounce rate computed over a denominator that is wrong. Nothing looks broken from the outside, which is why this usually survives for years. Remove the duplicate: most often a tag added directly to the theme AND through the tag manager, or a plugin adding the one you already had.
You run a consent platform, and these tracker scripts carry none of the blocking attributes consent platforms normally add: Google AdSense (https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=). WHAT WE CHECKED: the page's HTML source, for the conventions CMPs write onto a parked tag — type="text/plain", data-cookieconsent, data-cmp, data-consent, data-ot / the optanon class, and data-usercentrics. WHAT WE CANNOT SEE: we do not run the page's JavaScript, so we cannot observe whether these tags actually fire before consent is given — a platform may block them at runtime by another mechanism. Treat this as a prompt to verify your setup, not as a finding that you are non-compliant. If your CMP blocks these another way, nothing here needs changing.
✦Social presenceLinked profiles and share-ready Open Graph / Twitter cardsWarn · 60›
How this score is made60 of 100 points, 1 of 6 checks lost something
- Preview image20 / 20og:image is setThe Open Graph protocol makes og:image the field that turns a shared link into a card rather than a line of text, and Facebook, LinkedIn and X all read it. The largest share-readiness weight for that reason.
- Preview title15 / 15og:title is setOpen Graph protocol, required property. Weighted below the image because the fallback (the <title> tag) is usually acceptable, whereas there is no fallback for a missing image.
- Preview description10 / 10og:description is setOpen Graph protocol, optional but universally consumed. Our judgement on the weight: it fills the card's body text, and its absence degrades the preview rather than breaking it.
- Canonical share target10 / 10og:type and og:url setog:url is what makes shares of tracking-parameter variants consolidate onto one canonical target; og:type tells the platform what kind of object it is. Both Open Graph protocol; low weight because most platforms guess acceptably without them.
- X / Twitter card5 / 5twitter:card is declaredOur judgement, the smallest weight here precisely because X reads Open Graph as a fallback, so its absence is rarely visible to a reader.
- Linked profiles0 / 40no social profiles are linked from this pageOur judgement: linked profiles are how a reader and an entity-resolver both confirm the brand is the same one, and schema.org sameAs exists for exactly that. Full credit at 3 networks rather than all eight — three is enough to establish identity, and more is a marketing choice rather than a technical one.
This page links to no social profiles at all. That is the whole of the profile half of the score — the share-readiness half can be perfect and the card will still sit around 60, which is what the arithmetic above is showing you. Linking your profiles is also how schema.org's sameAs property gets its value: it is what tells Google and the answer engines that the brand on those profiles and the brand on this site are the same entity.
The Open Graph set is complete, so a shared link renders as a proper card with your title, description and image on every platform that reads it — including the ones you have not linked to.
What this card checks is the page — which profiles it links to, and whether the tags that build a share preview are present. It does not check what happens ON those profiles: follower counts, how recently you posted, or whether an account is still active. We would rather name that than imply we looked.
GBGoogle My BusinessBusiness profile presence, rating and reviewslocked›
Upgrade to Starter to analyze the Technical SEO checks live data for visibilityproof.com.
Upgrade to Starter →Upgrade to Pro to analyze the Fix-it answers live data for visibilityproof.com.
Upgrade to Pro →Upgrade to VisibilityProof to analyze the Step-by-step fixes for your platform live data for visibilityproof.com.
Upgrade to VisibilityProof →Upgrade to Pro to analyze the Backlink intelligence live data for visibilityproof.com.
Upgrade to Pro →Upgrade to VisibilityProof to analyze the Competitor share-of-voice live data for visibilityproof.com.
Upgrade to VisibilityProof →Upgrade to Starter to analyze the Keyword volume & difficulty live data for visibilityproof.com.
Upgrade to Starter →Upgrade to Starter to analyze the AI answer-engine tracking live data for visibilityproof.com.
Upgrade to Starter →Upgrade to Pro to analyze the Keyword trends live data for visibilityproof.com.
Upgrade to Pro →Upgrade to VisibilityProof to analyze the Google My Business live data for visibilityproof.com.
Upgrade to VisibilityProof →Upgrade to Pro to analyze the AI keyword demand live data for visibilityproof.com.
Upgrade to Pro →Upgrade to VisibilityProof to analyze the Search position & top-5 live data for visibilityproof.com.
Upgrade to VisibilityProof →Upgrade to VisibilityProof to analyze the ChatGPT citations & fan-out live data for visibilityproof.com.
Upgrade to VisibilityProof →Upgrade to VisibilityProof to analyze the Keyword opportunities live data for visibilityproof.com.
Upgrade to VisibilityProof →- INP (no CrUX field data — site has insufficient traffic)
- Core Web Vitals field data (showing lab data from Lighthouse)
- Orphan pages (requires a full-site crawl)
The same finding, at both fix-it depths
AI answer engines — no AI engine currently cites this site; only 40-59% of content is in the server HTML. Both answers below are the real ones from this audit, not examples of them.