A small business SEO audit should check, in this order: whether Google can index your pages, whether crawling, redirects and canonical tags point the right way, whether titles, descriptions and H1s are unique, how fast the site loads on a phone, whether your schema is valid, how pages link to each other, your local listings, your content, and whether AI search tools can reach you. Every one of those checks can be done with free tools.
The checklist is the easy part. The hard part is ranking what you find by impact, and throwing out the false alarms. Automated tools report plenty of problems that aren't real, and a 200-row export sorted by count sends you to fix the wrong things first.
Below is the checklist we use, the free tool for each check, and real numbers from an audit we did for Elume Medspa, a med spa in Fairfax, Virginia. Its site health score went from 54 to 75 in about two weeks of fixes.
- Fix in three tiers: things that stop pages being indexed, then problems on every page (templates), then single-page polish.
- Google Search Console, PageSpeed Insights and the Rich Results Test cover most of the audit for free.
- Verify every finding on the live site before you act. On one client site, eight findings across two audits turned out to be false.
- Small sites usually have no real-user speed data, so test lab speed three times and use the median.
- Measure after each fix. Some fixes, like rewriting a meta description, can do nothing at all.
How to prioritize: rank by impact, not by count
Most audit tools sort findings by how many pages they affect. That's misleading. One wrong setting that keeps your best service page out of Google matters more than 40 image alt tags.
We sort every finding into three tiers:
- Blockers. Anything that stops Google indexing or ranking a page: noindex tags, robots.txt blocks, broken redirects, pages stuck in "Discovered, currently not indexed."
- Sitewide multipliers. Problems baked into a template, so they hit every page at once. On Elume's site, a 786 KB icon script loaded on 100% of pages. One template fix reaches every URL.
- Page-level polish. Long titles, missing descriptions, missing alt text. Worth doing, but last.
Then measure. We rewrote the meta description on Elume's Botox page and measured no effect. The page's ranking position, not its snippet, was holding it back. That told us where the next hour should go.
The checklist at a glance
| # | Check | Free tool | Tier |
|---|---|---|---|
| 1 | Indexing | Search Console: Page indexing report, URL Inspection | Blocker |
| 2 | Crawl: robots.txt and sitemaps | Search Console: Sitemaps; your browser | Blocker |
| 3 | Redirects | curl -I or a redirect checker | Blocker |
| 4 | Canonical tags | URL Inspection; view source | Blocker |
| 5 | Titles and meta descriptions | Screaming Frog (free up to 500 URLs) | Polish |
| 6 | H1 headings | Screaming Frog; a real phone | Polish |
| 7 | Speed and Core Web Vitals | PageSpeed Insights; Search Console | Multiplier |
| 8 | Mobile layout | Chrome DevTools device mode; a real phone | Multiplier |
| 9 | Schema | Rich Results Test; Schema Markup Validator | Multiplier |
| 10 | Internal links | Screaming Frog; Search Console Links report | Multiplier |
| 11 | Images | Screaming Frog; PageSpeed Insights | Polish |
| 12 | Local | Your Google Business Profile; your own site | Multiplier |
| 13 | Content | Search Console Performance report | Varies |
| 14 | AI search access | robots.txt; your host's access logs | Blocker for AI tools |
The 14 checks, one by one
1. Indexing: is Google actually showing your pages?
Open the Page indexing report in Search Console and look at why pages aren't indexed. Then run your most important URLs through the URL Inspection tool, which shows whether the page is indexed, whether crawling is allowed, and which URL Google picked as the canonical.
On a small or new site, "Discovered, currently not indexed" often means Google hasn't got round to crawling the page, not that it judged it poor. For Elume we published 8 city pages; weeks later only 1 was indexed. Every URL we submitted with Request Indexing was crawled the same day and indexed. Every URL we didn't request stayed "Discovered." The site was crawl-starved, not low quality. Now we request indexing on publish day. There's a daily quota, so spend it on your most important pages.
2. Crawl: robots.txt and sitemaps
- Open
yoursite.com/robots.txt. Make sure nothing important is disallowed and the sitemap line useshttps://. - Submit your sitemap in Search Console and check it reports no errors.
- Check that
lastmoddates are real. On Elume's site, 86% of posts carried one identical bulk date, which tells Google nothing about what changed. - Clean up crawl waste: on Elume's site, paginated
/page/N/archive URLs now return 404, and we 301-redirected 3 legacy aliases.
3. Redirects: one hop, permanent
Every old URL should 301 straight to its new home in one hop. Chains slow crawling and leak value. Run curl -I on old URLs, or use any free redirect checker, and read each Location header yourself. We once retargeted a legacy three-hop redirect that ended on a retired domain to a single 301. If you've moved domains or platforms, our domain change guide covers this in depth.
4. Canonical tags
Each page should have a canonical tag pointing at its own preferred https:// URL. Elume's baseline audit found http:// canonicals, plus http:// URLs in robots.txt and the sitemap index. URL Inspection shows the "Google-selected canonical," so you can see whether Google agrees with you.
5. Titles and meta descriptions
Every page needs its own title and description. Google's title link guidance sets no character limit but truncates titles to fit the screen, so we keep titles to 60 characters or fewer, with the keyword and the town early. Google may also write its own snippet instead of your description. Unique ones still help.
Elume's baseline: 6 missing meta descriptions and 12 titles over 60 characters. After the fixes, the August 30 re-audit of 107 pages found zero missing or duplicate titles, zero over 60 characters, and zero missing or duplicate descriptions.
6. H1 headings
One clear H1 per page that says what the page is. Elume's homepage was the only page without one. The less obvious problem was on phones: on up to 66% of blog posts, the H1 was hidden behind the fixed header on mobile. A crawler can't see that. Only a phone can.
7. Speed and Core Web Vitals
Google's Core Web Vitals targets are a Largest Contentful Paint (LCP) of 2.5 seconds or less, Interaction to Next Paint of 200 milliseconds or less, and Cumulative Layout Shift of 0.1 or less, measured at the 75th percentile of real visits. Check them in PageSpeed Insights.
Here's the catch for small businesses: real-user ("field") data only appears if your site gets enough Chrome traffic. Neither of Elume's sites had any. You're left with lab tests, which swing a lot from run to run, so run each test three times and take the median.
From our work: On August 15, 2026, a treatment page on Elume Medspa's site went from a mobile Performance score of 58 to 94, and mobile LCP from 10.42 seconds to 2.35 seconds. That's lab data, the median of three Lighthouse runs. An earlier single-run reading we'd recorded didn't hold up on re-testing, so we retracted it and cite only the three-run medians.
Two more lessons. Elume's performance category score later fell from 83 to 62 because we switched to three-run medians, not because anything broke. And removing 367 KB per page load produced no measurable LCP change. On a site with noisy lab results, count bytes and requests, and don't trust one LCP run.
8. Mobile layout
Google retired its Mobile-Friendly Test in December 2023, so use Chrome DevTools device mode and, more importantly, your own phone. Check that the main call to action is visible without scrolling, tap targets are big enough, and nothing covers the page. Elume's Morpheus8 page had its booking button about 82 pixels below the first screen on a 375 by 812 phone screen. We moved it above the fold.
9. Schema (structured data)
Test key pages in the Rich Results Test. Look for one Organization or LocalBusiness node with your exact name and address, Service or Product markup that matches the visible page, and no errors. Don't add self-awarded star ratings, and don't add FAQPage markup expecting a rich result: Google stopped showing FAQ rich results on May 7, 2026. Elume's baseline had zero Service or MedicalProcedure markup; we added it to all 23 treatment pages, and the August 30 re-audit found zero invalid JSON-LD.
10. Internal links
Your most valuable pages should get the most internal links. Elume's blog linked to the online store 3.3 times as often as to the treatment pages, the opposite of what the business needed. We rebalanced it to 1.4 to 1. We also found 191 links pointing into category archives that were set to noindex, and took them to zero.
11. Images
Check alt text and explicit width and height on images. Elume's baseline: 89 of 433 images (20.6%) had no alt text and 19 pages had no social sharing image. Images missing dimensions went from 23 to 0 in the fixes.
12. Local
- Name, address and phone identical on your site, your Google Business Profile and directories. Elume's
/contact/page still showed an old street address. - Location words on service pages. 21 of Elume's 23 treatment pages never said where the clinic was.
- Town pages only if they're genuinely local. Thin copies with the town name swapped are doorway pages.
13. Content
Look for pages competing for the same search (cannibalization), near-duplicates and thin pages. Elume's online store had 46 of 141 blog posts that were near-duplicates in 12 competing groups. On the main site we merged a competing pair of microneedling pages with a 301. In Search Console's Performance report, look for queries where two of your URLs take turns ranking.
14. AI search access
Check that robots.txt allows the AI search crawlers, then check that your host isn't throttling them anyway. On Elume's site, the host was rejecting GPTBot on 62.5% of requests while Googlebot got through every time. Our GEO guide walks through it.
Check every finding against the live site
This is the lesson that saves the most time. Tools return clean, plausible, wrong answers, and nothing warns you.
From our work: During Elume's August 30 audit we retracted three findings as false positives: "107 images missing alt" was the Facebook Pixel's tracking beacon, not real images; "34 orphan pages" and "single-page app" were also wrong. On September 12, an external SEO and AI-search tool reported 5 problems that weren't real. It fetched pages as Markdown, which strips the <script> tags that hold schema, so it saw "no schema" and recommended FAQ markup Google no longer rewards and a self-awarded rating we'd removed on purpose.
Other false alarms we've hit:
- Bot protection. A plain
curlgot a 5.5 KB security challenge page instead of the 128 KB real page, which produced a false "zero links" finding. Check for an HTTP 200 and a plausible page size. - A false 404. A tool resolved a redirect's
Locationheader against the wrong host. Read the raw header. - Cached pages. Testing a cache-busted URL tells you nothing about what visitors get. We measured the same page at 2.35 seconds fresh and 9.99 seconds from a stale cache on the same day.
Don't skip the access check after a handover
If your site recently changed hands between developers or agencies, add one more check: who still has access, and what's sitting in public folders. When Elume switched web vendors on September 20, 2026, the handover was described as complete. Our check found a live admin account from the previous agency and a 29 MB database backup in a public folder, holding password hashes and booking records. Neither shows up in an SEO tool. Our website takeover checklist covers the rest.
What a good result looks like
For Elume, the main site's health score went from 54 on August 14, 2026 to 75 on August 30, across 107 pages and 12 specialist checks. On-page hygiene went to zero defects: no missing or duplicate titles, descriptions or H1s, no canonical problems, no stray noindex tags and no invalid schema.
Treat a score as a trend from one tool, measured one way. It isn't a ranking. The real test is in Search Console a few weeks later: more pages indexed, more impressions for the searches you care about, and more clicks.
If you have a small site and an afternoon, you can run this whole list yourself. If you'd rather have every finding verified and ranked for you, that's how our SEO audits work.
Frequently asked questions
How often should a small business do an SEO audit?
A full audit once or twice a year is enough for most small sites, plus a quick check after any redesign, platform move, domain change or change of web developer. Those events cause most of the serious problems we find.
How much does an SEO audit cost?
You can run every check in this article yourself for free. Paid audits range widely depending on site size and depth. What matters more than price is whether the findings are verified against the live site and ranked, or just exported from a tool.
Is a site health score from an SEO tool reliable?
Use it as a trend, not a grade. Each tool weighs things differently, and a change in how it measures can move the score without anything on your site changing. Compare scores only from the same tool, measured the same way.
Can an SEO audit hurt my site?
Reading your site can't hurt it. Acting on false findings can, for example adding markup Google no longer uses or deleting pages a tool wrongly called orphans. Heavy crawls can also trip your host's rate limits, so crawl slowly.