Guides: what matters on a website

Each guide takes one point and explains why it matters for your site, what the audit looks at and what we find on the sites we audit.

How these guides are written

Figures from our own audits

The figures come from the sites we have audited, with their period and their limits.

Sources you can open

Every rule we cite links to the official text: a law, a court ruling, an authority or a public register.

What the check does not tell you

Every guide ends with its limits: what an outside check cannot establish.

The guides, pillar by pillar

Security & encryption

HSTS: what it protects, and what can break

HSTS makes browsers use HTTPS from the very first request. What max-age, includeSubDomains and preload do, what breaks, and what the audit reads.

Read the guide →

Secure cookie attributes: what each stops

Secure, HttpOnly, SameSite: what each cookie attribute prevents, which cookies really need them, and what the audit records on your website.

Read the guide →

HTTP security headers: which ones matter

HSTS, CSP, X-Frame-Options: what each HTTP security header prevents, which ones come first, and what the audit records on your website.

Read the guide →

Performance

Largest Contentful Paint: what delays it

LCP measures when a page's largest visible element appears. Google's thresholds, the four steps where time is lost, and what our audit measures.

Read the guide →

Slow website: the causes in load order

A slow website rarely has a single cause. Here are the causes in the order a page runs into them, and what our audit measures at each step.

Read the guide →

SEO & search visibility

Redirect chains: why one hop is enough

A 301 redirect does its job in one hop. Why redirect chains cost you, where they come from, and what the audit checks on your site.

Read the guide →

SEO migration: before and after launch

A redesign can change every URL on your site. What to settle before launch, and what the audit remeasures once the new site is live.

Read the guide →

Robots.txt: what it actually blocks

Robots.txt controls crawling, not indexing. The lines a crawler silently skips, the mistakes nobody sees, and what our audit checks in your file.

Read the guide →

Structured data: which types still work

Organization, WebSite, BreadcrumbList, Article, Product: the structured data that still does something, and why it has to say what the page says.

Read the guide →

Accessibility

RGAA: France's accessibility standard

The RGAA is France's official method for checking web accessibility. Who must apply it, how it maps to WCAG, and what a conformance audit involves.

Read the guide →

WCAG 2.2 checklist: what blocks a visitor

WCAG 2.2 is the current W3C accessibility standard. Levels A and AA, the criteria that stop visitors, and what a checklist cannot tell you about your site.

Read the guide →

Accessibility statement: who needs one

An accessibility statement says how far a website meets the accessibility standard. Who must publish one in Europe, what it contains, and what we check.

Read the guide →

European Accessibility Act: who it covers

Since June 28, 2025, the EAA applies to websites that sell to consumers in the EU. Who is covered, which small businesses are exempt, and what to publish.

Read the guide →

Compliance & privacy

Website imprint requirements in the EU

What an EU business website must publish about who runs it, what France adds, and the flaw few people check: a legal notice no page links to.

Read the guide →

EU ecommerce legal requirements, explained

What an online store selling to EU consumers must display in 2026: identity, prices, guarantee, withdrawal, dispute body, order button and reviews.

Read the guide →

Domain & network

DNSSEC: what it does and doesn't protect

DNSSEC signs your domain's DNS answers so they can't be forged. What it covers, what it doesn't encrypt, who turns it on, and what the audit checks.

Read the guide →

DMARC: who can send email as your domain?

DMARC tells mailbox providers what to do with email that spoofs your domain. The three policies, the Gmail and Yahoo rules, and what the audit reads.

Read the guide →

Domain expiration: what stops, and when

When a domain expires, your website and email stop the same day. Why renewals fail even on auto-renew, and what the audit reads from the registry.

Read the guide →

Independence & resilience

CLOUD Act: is your website exposed?

The CLOUD Act reaches data held by US providers, even on servers in Europe. Which layers of your website it covers, and what the audit looks at.

Read the guide →

What your website sends outside the EU

A visit can send your visitor's IP address outside the EU (fonts, analytics, videos). Why it counts as a transfer, and what the audit records.

Read the guide →

EU web hosting: more than server location

A server in the EU is not enough: your host's jurisdiction, DNS, CDN and email matter too. The questions to ask before you choose.

Read the guide →

Content & trust

llms.txt: what it does and who reads it

llms.txt summarizes a website for language models. Google Search said on June 15, 2026 that it ignores the file. Who reads it, and what matters more.

Read the guide →

E-E-A-T: what Google means by it

Experience, expertise, authoritativeness, trust: what Google puts behind E-E-A-T, why it isn't a score, and what makes it visible on a page.

Read the guide →

Untranslated content on multilingual sites

A heading added later, a theme message, a reused block: where untranslated content hides on a multilingual website, and what the audit compares.

Read the guide →

Lorem ipsum left on a live website

Lorem ipsum is only the best-known kind. "[Insert name]" notes, XXXX dates, theme labels: the placeholder text that ships with a live website.

Read the guide →

User experience & reliability

JavaScript console errors: what breaks

A JavaScript error on page load can disable a menu or a form, or change nothing for visitors. What makes the difference, and what the audit records.

Read the guide →

Website images not showing: the causes

An image that's broken for every visitor comes from your site, not their browser. The causes, the files that break unseen, and what the audit records.

Read the guide →

Situations and site types

Free website audit: what a scan can't see

What a free website audit measures well, what one automated pass can't see, and what our free audit covers: one page, one pillar.

Read the guide →

Website audit tools: what each type checks

SEO, speed, security and accessibility tools: what each type of website audit tool measures well, what it skips, and when a human review changes the result.

Read the guide →

Website audit cost: what sets the price

What drives the cost of a website audit: pages reviewed, languages, topics covered, human review, deliverables. And our public price list, plan by plan.

Read the guide →

How to audit a website, pillar by pillar

What a website audit checks, in what order and why: which pages, the nine pillars, what needs a real browser, and how to read the score.

Read the guide →

Ecommerce website audit: what it checks

Trackers before consent, required consumer information, security, domain, checkout: what our audit checks on an online store, and what it finds.

Read the guide →

SEO audit vs website audit: the difference

An SEO audit checks that search engines read your pages. A website audit also covers security, legal, domain and accessibility. Which one you need.

Read the guide →

Competitor website audit: what it compares

Audit a competitor's website on all 9 pillars, scored exactly like yours: what a passive audit compares, and what stays invisible from outside.

Read the guide →

The audit's 9 pillars

Each guide belongs to one of them. Each chapter details what the audit checks on that pillar.

Security & encryption

Are your visitors' connections properly protected?

Performance

Does your site remain fast enough for its visitors?

SEO & search visibility

Can search engines understand your pages correctly?

Accessibility

Can people with different accessibility needs use your pages?

Compliance & privacy

Are the visible elements related to the obligations that apply to your site properly present and configured?

Domain & network

Are your domain and email infrastructure properly protected?

Independence & resilience

Who does your site depend on, and what happens if one of those dependencies becomes unavailable?

Content & trust

Is your content clear, credible and properly structured?

User experience & reliability

Do the pages and journeys that matter actually work?

Have all 9 pillars checked on your site

See pricing