All services

Site Audits & Compliance

Most website problems don’t announce themselves. Nobody emails you to say your checkout is unusable on a screen reader, that a plugin you installed three years ago has a known way in, or that Google has quietly indexed four hundred junk pages that are dragging down the rest of your site.

An audit is the process of finding those things on purpose, before they find you.

I go through your site the way an attacker would, the way a customer with a disability would, and the way a search engine does — then hand you a plain-English report. Not a hundred-page automated scan dump. A ranked list: what’s actually dangerous, what’s merely untidy, what each fix involves, and roughly what it costs. You decide what to act on. You can hand the list to me, to your existing developer, or sit on it — the report is yours either way.

1. Weak points, old plugins, and who has the keys

What it is
A review of everything installed on your site, everyone who can log into it, and every known way in.

Why it matters
Almost nobody is targeting your business by name. Automated software scans millions of sites a day looking for one specific weakness — a plugin version with a publicly documented flaw, an old admin account belonging to someone who left two years ago, a file permission set too loosely. Plugins are the usual culprit: a developer stops maintaining one, the flaw gets published, and every site still running it becomes a target. Meanwhile the plugin keeps working perfectly, so you have no reason to suspect anything.

How I handle it
I check every plugin and theme against public vulnerability databases and flag anything abandoned, out of date, or known to be exploitable. I review who has access and at what level — you’d be surprised how many sites have three or four accounts with full admin rights that nobody remembers creating. Then file permissions, login protection, exposed configuration files, and the settings that make automated attacks easy. Everything found comes with what it means in practice, not just a severity score.

2. Can everyone actually use your site?

What it is
A check of whether people with disabilities can navigate, read, and buy from your site — tested against the recognised international standard, WCAG 2.2 AA.

Why it matters
Roughly one in five people has a disability that affects how they use the web. Some navigate entirely by keyboard because they can’t use a mouse. Some use a screen reader that speaks the page aloud. If your menu can’t be opened without a mouse, or your product images have no description, or your form errors appear in red with no other signal, those customers simply leave — and you never see it in your analytics, because a visit that goes nowhere looks like any other bounce.

There’s a legal dimension too. Accessibility lawsuits against ecommerce sites have become routine in several markets, and automated accessibility widgets — the little floating accessibility button — have repeatedly failed to protect the sites using them.

How I handle it
Automated tools catch perhaps a third of real accessibility problems, so I use them as a starting point and then test by hand. I navigate your key journeys using only a keyboard, and again with a screen reader, to find out whether they can actually be completed. I check colour contrast, form labels and error messages, heading structure, image descriptions, and whether anything relies on colour alone to convey meaning. You get findings grouped by how much they actually block someone, with the specific pages and elements named.

What it is
A check that what your site actually does with visitor data lines up with what your policies and consent banner claim it does.

Why it matters
This is the gap that catches most businesses out. A site has a cookie banner and a privacy policy, so it looks compliant — but the tracking scripts fire before anyone clicks accept, the banner has no genuine way to decline, and the privacy policy is boilerplate that mentions services the site doesn’t use and omits the three it does. Analytics, ad pixels, chat widgets, and embedded videos all set cookies, and each one added over the years quietly widened the gap between the policy and the truth.

Regulators aside, the practical risk is straightforward: if your consent setup is broken, your analytics data is unreliable too, so you’re making decisions on numbers that don’t reflect reality.

How I handle it
I load your site fresh and record exactly what fires before consent, after accepting, and after declining — then compare that against your banner’s promises and your privacy policy’s text. I check that declining actually works, that consent is stored and honoured on return visits, and that your policy names the real services collecting data. Where your tracking is tied to advertising platforms, I check the consent signals are being passed correctly, since a broken setup there costs you conversion data as well as compliance.

You get a clear statement of what’s misaligned and what needs changing. I’ll flag legal exposure so you can raise it with a lawyer — I’m not one, and I won’t pretend a technical fix is legal sign-off.

What it is
A full crawl of your site to find dead ends, redirect chains, and low-value pages cluttering up search results.

Why it matters
Sites accumulate mess. Products get deleted, pages get renamed, a migration leaves half the old URLs pointing nowhere. Every broken link is a visitor who hit a dead end, and every redirect chain — a URL that bounces through three others before landing — slows the page down and dilutes the value search engines pass along.

Index bloat is the less obvious one. WordPress generates enormous numbers of pages nobody should ever land on: tag archives with one post, filtered product URLs in every combination, attachment pages, paginated duplicates. When search engines spend their limited crawling effort on those, your actual products and services get visited less often and updated more slowly in results. On a large store this is frequently the single biggest thing holding organic traffic back.

How I handle it
I crawl the whole site the way a search engine does and map what’s actually there against what’s actually indexed. That surfaces broken internal and outbound links, redirect chains and loops, duplicate content, missing or duplicated page titles, orphaned pages nothing links to, and the categories of junk URLs being indexed. Each finding comes with the fix — a redirect to write, a rule to exclude something from indexing, a link to repair — and an honest note on whether it’s worth your time, because plenty of crawl findings genuinely don’t matter.

5. A ranked fix list with real estimates — not a hundred-page PDF

What it is
Everything found, sorted by how much it matters and what it takes to fix, with time and cost against each item.

Why it matters
The reason most audits change nothing is that they’re unusable. An automated tool spits out four hundred issues, everything is flagged critical, and there’s no indication of which three things actually matter. Faced with that, most people close the file and carry on. A report that doesn’t lead to action was a waste of money regardless of how thorough it was.

How I handle it
Every finding gets two judgements: how much risk it carries, and how much work it is. That produces an obvious order of operations — the high-risk, low-effort items first, which is usually a surprisingly short list that removes most of your actual exposure in a day or two. Bigger structural items get grouped into phases you can budget for.

Each entry says what the problem is in plain terms, what happens if you ignore it, what fixing it involves, and an honest time estimate. Items that genuinely don’t warrant action are marked as such rather than padded in to make the report look substantial. You own the document. Hand it to me, hand it to whoever built the site, or work through it yourself — there’s no obligation attached.

Find out what’s actually wrong before someone else does.

Send me your URL and I’ll come back with the headline findings — what’s exposed, what’s blocking customers, and what I’d fix first. Plain English, fixed price, no obligation to have me do the work.