Most SEO audits don't change anything. Team commissions one, agency delivers a 200-page report, six months later traffic is down and the honest answer to "what got fixed" is "maybe a quarter of the recommendations, when somebody had time". That's the standard outcome, not the exception.
The audit isn't the problem. The framing is. Audits get treated as deliverables — billed, signed off, archived — when they're really just diagnostic snapshots. A snapshot is useless without the next step. And the next step almost never happens, because the report doesn't make it obvious which findings actually matter.
This article is about a different way to run them. It maps onto the SEO Audit tool we built at Algorithm, but the framework works whether you're using ours, three other tools, or a spreadsheet. The tool just automates the bookkeeping.
Four directions, run as one audit
A site has four layers of search performance, and each one shapes the others. Backlink profile. Content quality. Technical health. On-page configuration. You can audit them separately, and most tools will sell you that. The reason it doesn't work is that the problems they find are connected in ways a single-pillar audit can't see.
A real example I see often. Client comes in worried about traffic decline. Technical audit comes back clean — fast site, no crawl errors, schema validates. Content audit flags 200 articles scoring poorly on quality. Looks like a content problem, sounds like one, the team starts rewriting articles.
Three weeks in, we run the on-page audit. Half those poorly-scoring articles have canonical tags pointing at the homepage. They were never indexed in the first place. The "content problem" was never going to get fixed by rewriting content, because Google never saw the original content.
That's why the four pillars need to run connected. Otherwise you fix the wrong problem and call it progress.
Backlinks: stop paying for the data twice
Most audit tools sell their own backlink database. A different scrape than what's already in Semrush or Ahrefs, almost always smaller, often months out of date. Teams end up paying twice — once for the backlink tool they actually use, once for the audit tool's worse copy.
That's a business model, not a methodology. Bring your own data.
The audit takes a CSV, TSV, XLSX, or PDF export from Semrush, Ahrefs, GSC, Majestic — whichever you already pay for — and runs the analysis on those rows. What it actually looks for is patterns no DR score will surface.
Anchor text is the first thing I check. Natural profile sits around 30-40% branded anchors, 20-30% naked URLs, 15-25% generic ("click here", "this article"), 10-20% partial-match keywords, and 1-5% exact commercial. When exact-match commercials cross 25%, the profile reads as bought. When branded drops below 15%, same thing. Real editorial linking just doesn't produce those distributions.
After that comes link velocity. Forty new referring domains in two weeks, all from sites with overlapping IP ranges, all using similar anchor templates. Could be a campaign that worked. Could also be a paid placement run nobody mentioned. The spike isn't damning by itself — unexplained spikes are.
Then over-optimisation. Specific anchor strings repeating across dozens of placements. The same "best CRM software" pointing at the same target URL from twenty different sites in different verticals. That doesn't happen organically. Ever.
Last is genuine toxicity. Not low-quality, low-traffic, or unfamiliar — those are different things. Toxic means PBN footprints, hacked sites, scraped-content farms, link directories from a decade ago. The audit needs to explain which signals fired for each flagged link, because if you can't see what tripped the flag, you can't verify it. A black-box "toxic score" is just DR with worse PR.
A note on disavow, because this is where teams usually over-react. Disavow is a last resort, only for clearly manipulative links you couldn't get removed by request. Most low-quality links Google already ignores. Disavowing legitimate ones can actively hurt you, because the file is read as a signal that you don't trust your own profile. For deeper PBN and footprint analysis at the per-domain level, the Link Quality tool covers what a backlink-file audit can't reach.
Content: site-level scores are a lie
This is the part of the audit space that frustrates me most. Tools give you a "content score" for the entire domain. One number. Sometimes a letter grade. Sometimes a colour.
Google does not work that way.
Google evaluates each page individually, and the weak pages drag the strong ones down. A site with 100 strong articles and 400 weak ones doesn't average out to "okay" — Google reads quality signals across the full archive, weights the distribution rather than the mean, and the tail matters. Every weak article is dead weight. Every dead-weight article hurts the rankings of the pages you actually want to rank.
So a real content audit grades every article, not the site. Each one ends up in one of four buckets:
- Strong — solid information density, real authority signals, original research or experience. Don't fix it. Promote it. Internal links, distribution, schema, refresh in twelve months.
- Needs Work — topic is right, execution is partial. Two to four hours of editing rescues these. Highest-leverage rewrites because the foundation already exists.
- Rewrite — topic is valid, article needs to be rebuilt from scratch. Wrong angle, surface-level treatment, no expertise coming through. Full content cycle. Skip if low-traffic.
- Delete — no unique value, no traffic, no inbound links worth preserving. Remove with a 301 to the closest stronger article. Cutting dead weight consistently improves the rankings of surviving content, because Google stops splitting quality signals across pages that don't deserve them.
That's the spine. On top of that, a few specific checks worth running per article.
AI-generated content detection is one, and it's worth running carefully because both extremes give bad results. Pattern-based detection catches the obvious shapes — uniform paragraphs, repeated transitions, low entropy, clichéd phrasing. But modern AI output has learned to vary sentence length and avoid the words that used to give it away. So a regex-only layer produces too many false negatives. An LLM-only layer produces too many false positives. Both together catch what matters. We run the same logic as a standalone check inside Text Audit, for individual drafts before publishing.
Plagiarism is worth flagging selectively, never at scale. Running plagiarism on every article in a 1,000-page archive burns budget for marginal returns. Run it on the articles already flagged as low-quality or AI-suspect — that's where the real cases live. Articles that scraped competitor content during a sprint. Articles where a freelancer cut corners. Articles paraphrased so closely from one source that Google reads them as duplicate.
Cannibalisation is the highest-leverage finding in most content audits and the one most teams ignore. Two pages competing for the same query. Symptoms: rankings flickering between two URLs, impressions split across pages in Search Console, blog posts outranking product pages on transactional keywords. Sites with 200+ articles average 15-25 cannibalisation pairs. Some need merging. Some need re-targeting. Some need one of the two pages deleted outright.
E-A-T proxies are the last layer worth running per-article. Author bios that are actually real. Credentials. External presence. First-hand markers in the article — specific tools used, specific outcomes, real numbers, honest admissions of where something didn't work. The absence of these is itself a signal, and sites without identifiable authorship have been losing visibility through every quality update for years.
Technical: the basics, plus one thing that's new
The technical audit answers a single question: can search engines and AI assistants reach, render, and index every page that matters?
The basics are basic, and most haven't changed in a decade. Robots.txt for accidental blocks. Sitemap that lists only canonical 200-status URLs. HTTPS without mixed-content warnings. Security headers. Core Web Vitals from real-user data. Schema validates. Mobile renders. Hreflang reciprocates. CMS doesn't introduce its own special problems. None of that is interesting. All of it is necessary.
What's newer is AI crawler access. Worth opening your robots.txt and looking for explicit blocks on GPTBot, CCBot, PerplexityBot, ClaudeBot, and Google-Extended. The check itself isn't fancy — it's a robots.txt parse, nothing more. The reason to bother is that most teams have never looked, and an inherited block (from a CDN default, an old WordPress plugin, a robots.txt template someone copied two years ago) can quietly remove you from AI-generated answers. Either you blocked them on purpose, or you didn't. Either is fine. Not knowing is the problem.
One specific number worth tracking: server response time. TTFB above 600ms reliably correlates with reduced Googlebot crawl frequency. If the server's slow, Google throttles its crawling. New content takes longer to index. Existing pages get re-crawled less often. Sometimes a ranking decline you've been blaming on content quality is actually about hosting that quietly got slower over the last year.
The most common technical-audit mistake is testing only the homepage and assuming the rest of the site behaves the same way. It doesn't. Product pages load review widgets. Blog posts load embedded videos. Category pages load filter scripts. The homepage is usually the cleanest page on the entire domain — it tells you almost nothing about the pages users actually convert on.
On-page: title tags aren't enough
The on-page audit used to mean title length, meta description, H1 hierarchy, image alt, and schema. All of it still matters. None of it is enough on its own anymore.
TF-IDF analysis is one of the more useful additions. It compares your page's term distribution against the top-ranking pages for the target query. The signal isn't keyword stuffing — it's coverage. If the top ten pages all use a specific concept your page doesn't mention, that's a gap. If your page uses a term none of them use, you're either innovating or off-topic. Usually the latter.
People Also Ask coverage is worth checking before any rewrite. PAA boxes are Google itself telling you what users actually want to know about a topic. If five PAA questions appear for your target keyword and your page answers two of them, you have a coverage gap that's directly observable in the SERP. Filling it is one of the most predictable ranking improvements available.
Intent-keyword match is the on-page check most teams skip, and it's the one that breaks the most sites. A product page targeting an informational keyword will lose to a blog post. A blog post targeting a commercial keyword will lose to a product page. The fix isn't on-page optimisation — it's re-mapping the page to the right query, or re-mapping the query to a different page. The audit flags pages where the type and the intent don't line up, because no amount of title-tag tweaking fixes the underlying problem.
Internal link structure matters more than most audits credit it for. The wrong question is "does this page have internal links". The right ones are: how many, from where, with what anchors, and from pages with what authority. A page with weak internal linking is invisible to Google regardless of how good the content is. A page linked from your homepage and from your strongest blog posts gets surfaced faster than its standalone quality would suggest.
What this tool deliberately doesn't do
A few things we left out, on purpose. No DR or DA — vanity metrics, easily inflated through paid links, Google doesn't use them, and including them makes people use them. No backlink database — bring your export from whichever tool you already pay for, don't pay twice for the same data. No outsourced content analysis — we run our own analyser, your text doesn't get logged into a shared third-party model that trains someone else's product. No full-site crawls bundled into a subscription — audit the URLs that matter, not all 40,000 of them.
This positioning costs us users who want a one-screen dashboard with a big number on it. The trade is that the people who do use the tool get findings they can verify, on data they own, without paying for capacity they don't need.
Priority order is where most audits fail
This is where audits go wrong even when the findings are right. The audit produces 200 items, the team picks the easy ones, they fix things in the order that's psychologically satisfying instead of the order that unblocks downstream value. Three months later they've closed 80 tickets and traffic hasn't moved.
The right sequence is dictated by what each layer depends on, and it's the same on every site I've audited.
Technical blocks come first because they're binary. Broken canonicals, accidental noindex tags, robots.txt rules blocking important paths, server errors. Once these are fixed, pages become eligible for ranking. Without fixing them, nothing else compounds. Budget: one week.
Content quality and cannibalisation come second. Merge competing pairs, delete or redirect zero-value content, rewrite the worst offenders. This raises the site's average quality signal and frees crawl budget for pages that earn it. Budget: one month.
On-page optimisation of high-value pages comes third. Title tags, schema, internal links, intent alignment on the 20-50 pages that drive the most revenue or have the highest ranking ceiling. Budget: six weeks.
Backlinks come last. Disavow the genuinely toxic ones, identify gaps relative to competitors, build outreach. This isn't last because backlinks don't matter — they matter a lot. It's last because backlink improvements take months to surface in rankings, and acquiring links to pages that aren't indexed because of a canonical bug is the most common waste in SEO budgets I see.
Most teams reverse this order. They start with backlinks because backlinks feel like SEO, and link building is the visible work that gets prioritised. Three months later the pages still aren't indexed. Don't do that.
What to do in the next hour
If you can spend sixty minutes on this:
Open your /robots.txt. Read every line. Look for any Disallow: rule blocking paths you actually want indexed, and any User-agent: block targeting AI crawlers (GPTBot, CCBot, PerplexityBot, ClaudeBot, Google-Extended) that your team didn't deliberately add. Five-minute fix if you find one. Most teams have never looked.
Then pick five articles from your blog at random. Ask three questions of each: does it have a real author bio with credentials, three or more specific examples or numbers, and an actual point of view? If two out of five fail those questions, you have a content problem that's bigger than any technical or backlinks problem.
These two checks won't replace a full audit. They'll tell you whether you need one urgently or whether it can wait until next quarter.
The hard part of an audit isn't running the checks. The hard part is acting on what they tell you, especially when the answer is that the work you've been doing already hasn't been working.