Ecommerce website audit: what it checks
An ecommerce website audit checks what your store shows to a shopper, a search engine and the law: how fast product pages load on a phone, how the catalog is indexed, how data in transit is protected, which trackers fire before consent, the information owed to consumers, the domain name, and the providers the store depends on.
Our audit covers all 9 pillars, with weights set for online stores. It stops before payment: it never places an order.
What the audit looks at on a store
We pick the pages to analyze by how much they matter to your business, after grouping them by type: home page, category pages, product pages, brand pages, terms of sale. On each one, the audit records what actually happens in a browser, the way a visitor would see it.
- Compliance: trackers loaded before the visitor makes any choice, how cookies can be refused, the legal notice, then the information owed to shoppers, from the consumer dispute resolution body to how reviews are verified. Our guide to EU ecommerce legal requirements covers them one by one, and the one on the website legal notice covers seller identity.
- Security: encryption, the browser protection headers, and the cookies that carry the session or the login. Our guide to secure cookies explains what their attributes prevent.
- Performance: how long category and product pages take to display, under phone and desktop conditions. On a store, images are often the heaviest part. See what slows a website down.
- SEO: the tags on each page type, canonical URLs, and the redirects left behind by products taken out of the catalog.
- Accessibility: since June 28, 2025, the European Accessibility Act covers online sales to consumers, with an exemption for microenterprises.
- Domain and hosting: the domain expiration date, DNS protection, and the providers the store depends on, down to the CLOUD Act.
- Reliability: JavaScript errors and missing resources, page by page, and the controls that remain reachable on a phone.
For an online store, the weights put security and compliance first. The report states the weights applied to each pillar.
The checkout: what the audit does, and what it never does
The audit never places an order and never pays for anything. On the checkout pages it can reach without adding anything to the cart, it records third-party scripts unrelated to payment: advertising, analytics, social networks. The payment page usually requires a cart, sometimes an account. When it cannot be reached, the point is reported as not verified.
Walking the checkout to the final confirmation screen, to read the label on the button that commits the shopper to pay, is only done in a quoted audit where you authorize it. Adding an item to the cart opens a session, shows up in your analytics and can hold stock, so we don't do it without your permission. If that last screen asks for a name and address, we don't make one up, and the point stays unverified. Request a quote.
What we find on the stores we audit
80%load trackers (analytics, advertising, social networks) before the visitor has made a choice
90%haven't turned on DNSSEC, the signature that proves their domain's DNS answers are authentic
65%set at least one session or login cookie without its protective attributes
These percentages cover about 10 online stores we audited between August 14, 2026 and September 24, 2026, each counting only the stores where the point could be checked. Many were audited because a defect showed up quickly, so these figures describe our audits, not online stores in general.
Among the information owed to shoppers, a consumer dispute resolution body that is never named is the gap we run into most often. We have checked it on too few stores to give a percentage.
A sample: one store audit, published in full
The audit of a sporting goods marketplace is a real audit, anonymized. SEO and reliability score in the green: tags in place, no errors on the pages analyzed. Compliance is the lowest pillar. Refusing cookies takes two clicks where accepting takes one, a tag manager loads before any choice, no dispute resolution body is named, and the reviews on display don't say whether they are verified.
The report also finds a discrepancy that only shows up when pages are read side by side: returns described as free in the snippets Google displays, and charged to the buyer in the terms of sale.
An audit limited to SEO would not report any of this. Our guide on SEO audit vs website audit compares the two scopes.
Pricing, and what happens after you order
The price depends on the number of pages analyzed, not the number of products: pages are chosen by type, and the report lists every page analyzed. A60 is sized for an online store, at €890 excl. VAT. The other plans, and the whole-site audit on a quote, are on the pricing page. Our guide to website audit pricing explains what drives the cost.
Within 24 hours of your order, we review the store: if the plan doesn't fit it, you change or cancel at no cost. The report is delivered in 5 working days up to 60 pages, payment collected on delivery.
What this check doesn't tell you
We don't go past payment. No order is placed, and nothing that follows one is checked: confirmation email, shipping, returns, the online withdrawal function. The store's back office, inventory and sales figures are not visible from outside.
The report records facts, measurements and observable signs. It is not a compliance certification, legal advice or a penetration test.
Read next
EU ecommerce legal requirements, explained
What an online store selling to EU consumers must display in 2026: identity, prices, guarantee, withdrawal, dispute body, order button and reviews.
Read the guide →