Answer-engine visibility · Security · Speed
When AI answers, does your name come up?
We check whether ChatGPT, Perplexity, Gemini and Copilot can read, understand and recommend your site — then score the rest of it: conversion, security, compliance, speed and usability. About two minutes.
Sample report · 3 September 2026
northfield-outfitters.com
- Visibility
- 38
- Conversion
- 76
- Security
- 42
- Compliance
- 86
- Speed
- 62
- Usability & Design
- 84
- 43,044
- Known vulnerabilities tracked
- 18,211
- Plugins and themes covered
- 39,707
- Cross-referenced to public CVEs
Counted live from our advisory mirror and site registry.
AI search visibility
You can rank first on Google and not exist to ChatGPT.
Someone asks an answer engine for a supplier in your market, and it replies with a name. If it cannot crawl you, read you without JavaScript, or resolve you into a business worth citing, the name is a competitor’s — and no analytics tool you own will ever show you it happened.
01
Crawler access
We check twelve named AI crawlers against your robots.txt — OAI‑SearchBot, PerplexityBot, ClaudeBot, Google‑Extended and the rest. Block one and you are not ranked low in that engine, you are absent from it.
02
Readable without JavaScript
We fetch your page the way they do: raw HTML, no browser, nothing executed. Whatever appears only after JavaScript runs is content they never see.
03
Resolvable as a business
We look for the markup that names an organisation — who you are, what you sell, where to reach you. An engine cites what it can attribute and paraphrases what it cannot.
04
Quotable answers
We look for pages already in answer shape: a question, then a short reply. That is the form an engine can lift; an answer buried mid-paragraph is one it has to rewrite, or skip.
Then we ask them directly.
We put real buying-intent questions about your market to a web-grounded model and record what comes back — including which competitors it recommends instead of you. The report names the model and prints the exact questions asked, so you can repeat it yourself.
What we scan
One run, six stops, every check named.
The audit walks your site in this order. Every stop below names what it actually looks at — these are the checks the report prints, not a summary of them.
Revenue
Visibility
Can customers find you on Google and in AI answers (ChatGPT, Gemini)?
- robots.txt
- 12 named AI crawlers
- Raw HTML, JavaScript off
- Entity & Q&A schema
- Title, canonical, sitemap
- Live model questions
Revenue
Conversion
How much of your traffic turns into enquiries or sales
- Checkout reachable
- Guest checkout
- Payment options
- Returns & delivery policies
- Product schema
- Trust signals
Risk
Security
Exposure to breaches, data loss and downtime
- TLS version & expiry
- Security headers
- Mixed content
- Cookie flags
- Exposed files & user enumeration
- Every version vs published advisories
Risk
Compliance
GDPR, cookies, and the European Accessibility Act (in force since June 2025)
- WCAG 2.2
- Cookies before consent
- Trackers before consent
- Consent platform
- Policy link
Experience
Speed
Every extra second of load time costs conversions
- Largest Contentful Paint
- Layout shift
- Blocking time
Experience
Usability & Design
Where visitors get confused, stuck, or leave
- The rendered page, read by a model
- Where visitors get stuck
What it costs to not know
The damage is measured, not imagined.
Daily monitoring
An audit is a photograph. Your site is a moving target.
A site that passed clean this morning can be vulnerable by tomorrow — not because anything on it changed, but because someone published an advisory about a plugin it has been running for two years.
We record what you run
Core, plugins and themes, with exact versions.
We check it every day
A precise range match against those versions, not a guess.
We re-verify before we alarm you
We re-probe the live site first. Already patched, alert dropped.
Then we email you — and only then
No digest, no newsletter. One message, one-click unsubscribe.
Before you ask
The usual questions.
What does Critical Audit actually check?
Every audit scores six categories, two under each of three pillars:
Revenue — what the site earns
- Visibility — whether customers can find you on Google and in AI answers (ChatGPT, Gemini, Perplexity)
- Conversion — how much of your traffic turns into enquiries or sales
Risk — what can hurt or sue you
- Security — exposure to breaches, data loss and downtime, including known CVEs and out-of-date software you run
- Compliance — GDPR, cookies, and the European Accessibility Act, in force since June 2025
Experience — what customers feel
- Speed — every extra second of load time costs conversions
- Usability & design — where visitors get confused, stuck, or leave
You get one overall score, a score per category, and every finding ranked by what it costs you.
How long does an audit take?
Usually a couple of minutes. We fetch your pages, run the full analysis, then email you a link to your report. You see a preliminary score on screen while it runs, and the full report opens in your browser — every finding ranked, with what it takes to fix it. Nothing to download, and the link keeps working, so you can send it to whoever does the work.
Do I need to install anything on my site?
No. The audit runs entirely from the outside, exactly the way a visitor — or a search engine — sees your site. There is no plugin, no script tag and no access to your server or admin panel.
Find out what they see.
Your score, and every finding ranked by what it costs you. If it comes back clean, that is a useful thing to know too.