Website Tracking & Analytics Audit
PayHelm

Website Tracking & Analytics Audit

Free SEO + tracking audit — see exactly what's broken in under 60 seconds

Full GTM config is private — this reports the observed runtime container (what actually loads & fires). We'll email your report to the address above.

Last scanned Sep 11, 2026 — scored warn. Same result as last time.
Works, with issueshttps://glyphware.ca/

The audit of your website's home page reveals a few areas that need attention. Currently, Google Analytics 4 (GA4) is set up but is not firing correctly due to a Content Security Policy (CSP) issue, which is preventing the necessary scripts from loading. This is a critical gap as it means your site is not collecting analytics data as expected. Additionally, there is no Google Tag Manager (GTM) container detected, which is typically used for managing tags more efficiently. For Shopify-specific analytics, such as Trekkie or the Web Pixels API, none are present or firing, indicating a lack of native Shopify tracking infrastructure. There are no duplicate pixel risks since no Shopify analytics are detected. To ensure comprehensive tracking, the next steps should include auditing product pages, cart, checkout, and order-confirmation pages. Given the current issues, I recommend connecting your store to PayHelm AI for a more thorough analysis and assistance in resolving these tracking gaps.

Tracking Health: 59/100 · FSEO Score: 93/100 · AAI SEO Score: 54/100 · D
Overall Tracking Health
59out of 100Grade FPoor
Tag manager installed12/20

Tag setup present but not confirmed loading.

GA4 tracking10/20

GA4 configured but no hits observed (may be consent-gated).

Pageview / event coverage10/20

Not an ecommerce store — scored on basic analytics coverage.

Data quality15/15

No data-quality issues found in tracked events.

Consent Mode0/10

Consent Mode not detected.

Performance7/10

Tag load timing not measured.

No conflicts5/5

No conflicting analytics IDs.

Advanced Tracking Features
Consent Mode v2Info

No Google Consent Mode was detected. This mainly matters if you run Google Ads with EEA/UK traffic — no Google Ads pixel was seen on this site, so it's lower priority for now.

default: noupdate: no✗ ad_user_data✗ ad_personalization
Tag PerformanceInfo

No tag load timing was captured (the container may not have loaded, or timing was unavailable).

DOM ready 0.51sPage load 0.76s
Cross-domain TrackingInfo

No cross-domain (linker) tracking was detected. If your checkout or other steps live on a different domain, set up linker tracking so visits aren't split into separate sessions.

Enhanced ConversionsInfo

Google Ads Enhanced Conversions were not detected. They send hashed first-party data (email/phone) to recover conversions lost to cookie restrictions — worth enabling if you run Google Ads.

User-ID TrackingInfo

GA4 User-ID tracking was not detected. If you have logged-in users, setting a User-ID lets GA4 join their activity across devices and sessions.

SEO Review
93out of 100Grade AExcellent

SEO basics are mostly in place with a few opportunities to improve.

Title tagPass

Title is 59 characters — within the ideal 30–70 character range.

Glyphware — Toronto Digital Agency for Web Design & SEO (59 chars)
Meta descriptionPass

Meta description is 124 characters — within the ideal 70–160 character range.

Toronto digital agency for UX/UI design, web development, SEO, and AI automation. Serving Toronto, M… (124 chars)
H1 headingPass

One H1 heading found — the recommended structure for every page.

lyphware
Robots / indexabilityPass

No noindex directive — the page is eligible to be indexed.

No robots meta tag (defaults to index, follow).
Canonical URLPass

Canonical tag points to the page itself — no duplicate-content signals sent to search engines.

https://glyphware.ca
Open Graph tagsWarning

1 Open Graph tag(s) missing. Complete the set for consistent social link previews.

og:title ✓ og:description ✓ og:image ✗
Structured data (Schema.org)Pass

Structured data found — search engines can use it to generate rich results (star ratings, FAQs, products, breadcrumbs, etc.).

JSON-LD script found
Mobile viewportPass

Viewport meta tag found — the page is set up for mobile-friendly rendering.

viewport meta tag present
AI Discovery & AI SEOBlocked for AI
54out of 100Grade DNeeds work

Blocked: AI crawlers are actually refused at the server level (HTTP 403) when they try to fetch this site.

llms.txt fileWarning

llms.txt exists but doesn't follow the standard format. Use a top-level heading plus markdown links to your most important pages.

Found at /llms.txt but missing the expected structure (a top-level # heading and markdown links).
skill.md fileInfo

No skill.md file found. This is an emerging convention for describing agent-callable capabilities/tools to AI agents — optional today, but worth watching as adoption grows.

No /skill.md or /.well-known/skill.md found.
AI crawler access (robots.txt)Pass

robots.txt doesn't block any major AI crawler — ChatGPT, Claude, Perplexity, and Google's AI features can all fetch and cite your content.

All 15 known AI crawlers are allowed.
Live AI crawler testFail

We fetched your homepage using GPTBot's real User-Agent and it was refused (HTTP 403). This is a server/firewall-level block — AI crawlers cannot read this site at all, regardless of what robots.txt says.

GPTBot's User-Agent received HTTP 403.
Structured data for AI answersPass

Structured data (JSON-LD) is present with types AI answer engines commonly extract facts from (e.g. FAQPage, Product, Organization).

Schema.org types found: Organization, WebSite.
Server-rendered contentPass

Meaningful text content is present in the raw HTML response — AI crawlers that don't execute JavaScript can still read and cite this page.

~368 words of text visible in the raw HTML response.
XML sitemapPass

A sitemap is available at /sitemap.xml, helping both search engines and AI crawlers discover your full set of pages efficiently.

Found at /sitemap.xml.
llms.txt / skill.md link integrityInfo

There were no outbound links in llms.txt or skill.md to check for hallucinated endpoints or domains.

No links found to verify.
AI crawlers
GPTBot ✓OAI-SearchBot ✓ChatGPT-User ✓ClaudeBot ✓Claude-Web ✓anthropic-ai ✓PerplexityBot ✓Perplexity-User ✓Google-Extended ✓Applebot-Extended ✓Bytespider ✓CCBot ✓Amazonbot ✓cohere-ai ✓Meta-ExternalAgent ✓
Opportunities
  • Reformat llms.txt to follow the standard: a top-level `# Site Name` heading, a one-line summary, then markdown links (`[Page](url): description`) to your key pages.
  • AI crawlers get blocked at the server level (HTTP 403) when fetching your homepage, even though this may not show up in robots.txt. Check your WAF/CDN's bot-management rules for a User-Agent block on AI crawlers.
No GTM container was detected on this page.
Checks
GTM containerWarning

No GTM-XXXX container; gtag.js present instead.

Tags are loaded directly via gtag.js rather than through Tag Manager. That works, but you lose GTM's centralised management, versioning, and conditional firing controls.

Fix this issue
GA4 firingWarning

G-152WENDH2F — no /g/collect hit observed.

GA4 is configured but we did not see it send data on this page — it may be gated behind cookie consent or misconfigured.

Fix this issue
JavaScript errors during loadInfo

3 error(s) logged.

JavaScript errors were logged during page load. These don't necessarily affect tracking — only errors that directly interrupt pixel execution matter. See any vendor-specific errors below for actionable issues.

Google Consent Mode v2Info

No consent API calls observed

No Google Consent Mode was detected. This mainly matters if you run Google Ads with EEA/UK traffic — no Google Ads pixel was seen on this site, so it's lower priority for now.

Tag load performanceInfo

DOMContentLoaded 508ms

No tag load timing was captured (the container may not have loaded, or timing was unavailable).

Cross-domain trackingInfo

No linker configuration observed

No cross-domain (linker) tracking was detected. If your checkout or other steps live on a different domain, set up linker tracking so visits aren't split into separate sessions.

Enhanced Conversions (Google Ads)Info

Not detected

Google Ads Enhanced Conversions were not detected. They send hashed first-party data (email/phone) to recover conversions lost to cookie restrictions — worth enabling if you run Google Ads.

User-ID tracking (GA4)Info

Not detected

GA4 User-ID tracking was not detected. If you have logged-in users, setting a User-ID lets GA4 join their activity across devices and sessions.

Ecommerce Funnel — Not Applicable

This site doesn't appear to be an online store, so the ecommerce funnel report has been skipped. GTM tag coverage, triggers, variables, and on-page scripts are still audited above.

If this site does sell products, try re-running the audit on a product page URL — that will surface add-to-cart, checkout, and purchase event coverage.

On-page Scripts — Should Be in GTM (1)

These tracking scripts are hardcoded directly in your page HTML. Moving them into GTM makes them easier to update, pause, version, and conditionally fire — without touching your code.

Google Analytics 4 (direct gtag.js)

GA4 gtag.js snippet installed directly in the page HTML (outside GTM).

Fix: Remove the hardcoded GA4 snippet and manage it via a GTM 'Google Analytics: GA4 Configuration' tag.

Risk: Running GA4 both directly and via GTM sends duplicate pageviews and inflates every metric in your reports.

JavaScript errors (3)

Refused to load the script 'https://www.googletagmanager.com/gtag/js?id=G-152WENDH2F' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

Refused to load the script 'https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src

Refused to load the script 'https://www.googletagmanager.com/gtag/js?id=G-152WENDH2F' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

Your tracking has gaps — PayHelm can fix this.

Broken tags mean lost attribution and bad decisions. PayHelm unifies your ecommerce, ad, and analytics data so every number is trustworthy — no guesswork.

Ask a follow-up question