Skip to content
Available for new work

The ecommerce audit checklist, and what a checklist can’t find

This is the checklist I work through on an ecommerce store, grouped the way the problems cluster: speed, findability, product pages, checkout, tracking, AI visibility, and the code and plugins underneath. You can run most of it yourself in an afternoon. What a checklist can’t do is tell you which finding is costing the most, or why, and that’s the part at the end.

DC · 28 September 2026 · 13 min read

The ecommerce audit checklist, and what a checklist can’t findAI-generated

An ecommerce audit checklist is useful for one thing above all: finding the obvious problems cheaply, before paying anyone. Most stores have a few that anyone can spot with a phone, a private browser window and Google’s free tools. This checklist is grouped the way problems cluster in the stores I audit, so a failure in one section usually tells you where to look next.

What a checklist can’t do is rank what it finds by what each problem costs, trace a symptom to its cause in the code, or see how two systems are fighting each other. That’s the difference between a list and an audit, and it’s set out at the end with a real example.

Speed, template by template

Speed is where most checklists go wrong, because they measure one page and call it the site. A store isn’t one page; it’s a set of templates, and one slow template can lose the customers who matter most.

Measure every kind of page

Two pages from the same store, timed the same way on the same day, in an audit I carried out for a UK retailer in September 2026: the front page’s main image took 4.3 seconds to appear on a phone, and the gallery page took 17.5 seconds. A sitewide score would have averaged them and called the store slow-ish. Measured template by template, the problem had an address.

◆ One store, two templates, one day

4.3 s
front page, main image on a phone
Audit, UK retailer, September 2026
17.5 s
gallery page, same test
Audit, UK retailer, September 2026
4 s
where Google’s verdict turns to “poor” for LCP
Google, Core Web Vitals

The checks

  • Every template. Home, a category, a product, search results, basket and checkout, each run through PageSpeed Insights on mobile.
  • Field data first. Read the real-visitor data at the top of the report before the lab score.
  • Google’s lines. Main content within 2.5 seconds, a response to a tap within 200 milliseconds, layout shift of 0.1 or less.
  • The heaviest thing. Note what the largest element is on each template: often a hero image, a slider or a video.
  • Apps and tags. Count the third-party scripts loading on the product page.

Why it matters

Google’s Core Web Vitals judge a site at the 75th percentile of page loads, so the slowest quarter of your visitors decide your score. The Core Web Vitals self-check explains each metric in plain English.

Two kinds of finding: whether Google can find the store, and whether customers can find products once they’re on it.

Search engines

  • Indexed. Search Google for site: followed by your domain, the check Google itself suggests. Compare the count with how many products and categories you have.
  • Search Console. Verified, sitemap submitted, and the Page indexing report read for noindex and blocked pages.
  • Titles and descriptions. Each category and product has its own, written for a person, not left as the default.
  • Redirects. Old addresses from past redesigns or migrations redirect to the right new page, not the home page.

For the full version on a Shopify store, see why a Shopify website isn’t showing up on Google.

On-site search and navigation

  • Search. Try misspellings, plurals and a product code. Does search still find the product?
  • Filters. Do the filters on your biggest category narrow it to something a person would choose from?
  • Navigation. Can someone reach your best-selling category in two taps on a phone?
  • Empty results. What does a search with no results show? A dead end, or suggestions?

Product pages and trust

A product page has one job: give a buyer everything they need to decide. Most fall short in the same few places.

The checks

  • Your own words. Descriptions written for your customers, not pasted from the supplier.
  • The deciding details. Sizes, materials, dimensions, compatibility, whatever your customers ask before buying.
  • Images. Several, sharp, with a scale reference where size matters, and alt text on each.
  • Delivery and returns. Cost, speed and returns stated on the product page, not only in a policy page.
  • Stock. What happens when a size is out of stock: hidden, marked, or selectable and then refused at checkout?

The pages that have to be there

  • Contact. A real way to reach you, easy to find.
  • Policies. Delivery, returns, terms and a privacy notice, current and linked from the footer.
  • Cookies. A consent banner that actually blocks non-essential tracking until someone agrees.

Basket and checkout

This is where the money is lost, and the checks are simple to run yourself.

  • A test order. Buy something as a guest, on a phone, to an address outside your home area, with a card that’s never been used on the site.
  • Costs up front. Delivery costs visible before checkout, not discovered at the last step.
  • Guest checkout. Possible without creating an account.
  • Fields. Count the form fields. Baymard’s research suggests 12 to 14 form elements are enough.
  • Payment methods. Card plus the wallets your customers use, shown clearly.
  • Errors. Enter a wrong postcode and a declined card. Are the error messages clear, and does the form keep what was typed?

Where checkouts lose people goes through the method for finding which step leaks, and why.

Tracking and data

An audit is only as good as the numbers behind it, and broken tracking is a common finding. Check it before trusting any report.

The checks

  • Checkout events. GA4’s checkout journey report needs begin_checkout, add_shipping_info and add_payment_info events. Empty steps mean missing tracking.
  • Revenue matches. Compare a month’s revenue in analytics with the orders in your store admin. A big gap means lost or duplicated tracking.
  • Tags firing once. In Tag Manager’s preview mode, check purchase and add-to-cart tags fire once, not twice.
  • Consent. Tracking tags wait for consent where the banner says they will.
  • Product feed. Merchant Center shows no disapproved products for reasons you can fix.

Google’s checkout journey report is under Monetization in GA4 once the events are in place.

AI visibility

AI assistants now answer shopping questions directly, and they can only recommend what they can read.

  • Crawlers allowed. robots.txt lets in the search crawlers for ChatGPT, Perplexity and Google.
  • Content without JavaScript. Product names, prices and descriptions are in the page’s HTML, not added later by scripts.
  • Structured data. Product markup with price, availability, brand and images, and it parses.
  • Snippets allowed. No nosnippet or noindex on pages you want found. Google says its AI features need nothing more than an indexed page that can show a snippet.

The free AI visibility checker scores a page on all four. Google’s own guidance on AI features is short and worth reading.

Code, plugins and security

This is the section a checklist covers worst, because most of it needs access. But some of it anyone can check.

  • Platform version. Is it still supported and getting security patches? For Magento, see which versions are still supported.
  • Apps and extensions. List every one, what it does and when it was last updated. Remove anything unused properly, code included.
  • Admin access. Every admin user still needed, each with their own login and two-factor authentication.
  • Backups. You know where the last backup is and have seen one restored.
  • Payment page. Nothing on the checkout loads from a domain you don’t recognise.

What a checklist can’t find

A checklist tells you what’s wrong. It can’t tell you three things that decide what to do about it.

Which problem costs the most

One health check I carried out in September 2026 turned up twenty findings across four areas of a UK retailer’s store. Seven were critical, costing sales at the time; eight were major; three were minor and two cosmetic. A checklist would have produced the same twenty ticks and crosses in no particular order. Ranked by what each one cost, the first seven were obvious, and the last two could wait indefinitely.

◆ One health check, twenty findings

7
critical: costing sales at the time
Health check, UK retailer, September 2026
8
major: costing sales, or will
Same report
5
minor or cosmetic: worth doing alongside, or not urgent
Same report

Why it’s happening

A checklist sees the symptom: the gallery page is slow. It doesn’t see that the slowness comes from one app loading full-size images, or a database query that grew with the catalogue. Finding the cause usually means reading the code, the analytics and the server together, which is what the backend audit is for.

How the pieces interact

Two apps that each pass a checklist can break each other on the checkout. A tracking fix can double-count revenue in another report. The problems that cost most are often in the gaps between systems, where no single check looks.

What it’s worth fixing

A checklist treats every failure as equal. A business can’t: it has a budget and a year. The useful output of an audit is an order of work, with the cost of each fix against what it’s likely to return.

From checklist to audit

◆ When the checklist is enough, and when it isn’t

The checklist is enough when

  • The problems it finds are obvious and cheap to fix
  • You have the time and access to fix them yourself
  • The store is small and has few systems
  • You want a first look before spending anything

An audit earns its cost when

  • The numbers are falling and the checklist doesn’t say why
  • You need the findings ranked by what they cost
  • Several systems are involved: ERP, feeds, apps, custom code
  • A big decision, such as a replatform, depends on it

Where to go next

A health check takes one of these sections, reads it properly from the outside and ranks what it finds; the visual audit does every template against your competitors. What an ecommerce audit costs sets out what each level includes.

◆ Glossary

Template
One page layout used by many pages, such as the product page. Speed and problems are best measured per template.
Field data
Speed measured from real visitors, as opposed to a single simulated test.
Structured data
Code in a page that describes it to machines, such as a product’s price and availability.
Checkout journey report
A GA4 report showing how many people complete each step of the checkout.
Merchant Center
Google’s tool for the product feed behind Shopping results and free product listings.
Two-factor authentication
A second check at login, such as a code on your phone, on top of the password.

◆ Sources

◆ WRITTEN BY DC

18 years building and auditing software and ecommerce systems across 16 sectors. This is what I do, in public. If your numbers feel off, I'll tell you where they're going.

Available for new work

UK based · PHP · Python · JS · TS. Every first call is free.