Website Tracking & Analytics Audit
Free SEO + tracking audit — see exactly what's broken in under 60 seconds
The audit of your website's home page reveals a few areas that need attention. Currently, Google Analytics 4 (GA4) is set up but is not firing correctly due to a Content Security Policy (CSP) issue, which is preventing the necessary scripts from loading. This is a critical gap as it means your site is not collecting analytics data as expected. Additionally, there is no Google Tag Manager (GTM) container detected, which is typically used for managing tags more efficiently. For Shopify-specific analytics, such as Trekkie or the Web Pixels API, none are present or firing, indicating a lack of native Shopify tracking infrastructure. There are no duplicate pixel risks since no Shopify analytics are detected. To ensure comprehensive tracking, the next steps should include auditing product pages, cart, checkout, and order-confirmation pages. Given the current issues, I recommend connecting your store to PayHelm AI for a more thorough analysis and assistance in resolving these tracking gaps.
Tag setup present but not confirmed loading.
GA4 configured but no hits observed (may be consent-gated).
Not an ecommerce store — scored on basic analytics coverage.
No data-quality issues found in tracked events.
Consent Mode not detected.
Tag load timing not measured.
No conflicting analytics IDs.
No Google Consent Mode was detected. This mainly matters if you run Google Ads with EEA/UK traffic — no Google Ads pixel was seen on this site, so it's lower priority for now.
No tag load timing was captured (the container may not have loaded, or timing was unavailable).
No cross-domain (linker) tracking was detected. If your checkout or other steps live on a different domain, set up linker tracking so visits aren't split into separate sessions.
Google Ads Enhanced Conversions were not detected. They send hashed first-party data (email/phone) to recover conversions lost to cookie restrictions — worth enabling if you run Google Ads.
GA4 User-ID tracking was not detected. If you have logged-in users, setting a User-ID lets GA4 join their activity across devices and sessions.
SEO basics are mostly in place with a few opportunities to improve.
Title is 59 characters — within the ideal 30–70 character range.
Glyphware — Toronto Digital Agency for Web Design & SEO (59 chars)Meta description is 124 characters — within the ideal 70–160 character range.
Toronto digital agency for UX/UI design, web development, SEO, and AI automation. Serving Toronto, M… (124 chars)One H1 heading found — the recommended structure for every page.
lyphwareNo noindex directive — the page is eligible to be indexed.
No robots meta tag (defaults to index, follow).Canonical tag points to the page itself — no duplicate-content signals sent to search engines.
https://glyphware.ca1 Open Graph tag(s) missing. Complete the set for consistent social link previews.
og:title ✓ og:description ✓ og:image ✗Structured data found — search engines can use it to generate rich results (star ratings, FAQs, products, breadcrumbs, etc.).
JSON-LD script foundViewport meta tag found — the page is set up for mobile-friendly rendering.
viewport meta tag presentBlocked: AI crawlers are actually refused at the server level (HTTP 403) when they try to fetch this site.
llms.txt exists but doesn't follow the standard format. Use a top-level heading plus markdown links to your most important pages.
Found at /llms.txt but missing the expected structure (a top-level # heading and markdown links).No skill.md file found. This is an emerging convention for describing agent-callable capabilities/tools to AI agents — optional today, but worth watching as adoption grows.
No /skill.md or /.well-known/skill.md found.robots.txt doesn't block any major AI crawler — ChatGPT, Claude, Perplexity, and Google's AI features can all fetch and cite your content.
All 15 known AI crawlers are allowed.We fetched your homepage using GPTBot's real User-Agent and it was refused (HTTP 403). This is a server/firewall-level block — AI crawlers cannot read this site at all, regardless of what robots.txt says.
GPTBot's User-Agent received HTTP 403.Structured data (JSON-LD) is present with types AI answer engines commonly extract facts from (e.g. FAQPage, Product, Organization).
Schema.org types found: Organization, WebSite.Meaningful text content is present in the raw HTML response — AI crawlers that don't execute JavaScript can still read and cite this page.
~368 words of text visible in the raw HTML response.A sitemap is available at /sitemap.xml, helping both search engines and AI crawlers discover your full set of pages efficiently.
Found at /sitemap.xml.There were no outbound links in llms.txt or skill.md to check for hallucinated endpoints or domains.
No links found to verify.- Reformat llms.txt to follow the standard: a top-level `# Site Name` heading, a one-line summary, then markdown links (`[Page](url): description`) to your key pages.
- AI crawlers get blocked at the server level (HTTP 403) when fetching your homepage, even though this may not show up in robots.txt. Check your WAF/CDN's bot-management rules for a User-Agent block on AI crawlers.
No GTM-XXXX container; gtag.js present instead.
Tags are loaded directly via gtag.js rather than through Tag Manager. That works, but you lose GTM's centralised management, versioning, and conditional firing controls.
Fix this issueG-152WENDH2F — no /g/collect hit observed.
GA4 is configured but we did not see it send data on this page — it may be gated behind cookie consent or misconfigured.
Fix this issue3 error(s) logged.
JavaScript errors were logged during page load. These don't necessarily affect tracking — only errors that directly interrupt pixel execution matter. See any vendor-specific errors below for actionable issues.
No consent API calls observed
No Google Consent Mode was detected. This mainly matters if you run Google Ads with EEA/UK traffic — no Google Ads pixel was seen on this site, so it's lower priority for now.
DOMContentLoaded 508ms
No tag load timing was captured (the container may not have loaded, or timing was unavailable).
No linker configuration observed
No cross-domain (linker) tracking was detected. If your checkout or other steps live on a different domain, set up linker tracking so visits aren't split into separate sessions.
Not detected
Google Ads Enhanced Conversions were not detected. They send hashed first-party data (email/phone) to recover conversions lost to cookie restrictions — worth enabling if you run Google Ads.
Not detected
GA4 User-ID tracking was not detected. If you have logged-in users, setting a User-ID lets GA4 join their activity across devices and sessions.
Ecommerce Funnel — Not Applicable
This site doesn't appear to be an online store, so the ecommerce funnel report has been skipped. GTM tag coverage, triggers, variables, and on-page scripts are still audited above.
If this site does sell products, try re-running the audit on a product page URL — that will surface add-to-cart, checkout, and purchase event coverage.
These tracking scripts are hardcoded directly in your page HTML. Moving them into GTM makes them easier to update, pause, version, and conditionally fire — without touching your code.
GA4 gtag.js snippet installed directly in the page HTML (outside GTM).
Fix: Remove the hardcoded GA4 snippet and manage it via a GTM 'Google Analytics: GA4 Configuration' tag.
Risk: Running GA4 both directly and via GTM sends duplicate pageviews and inflates every metric in your reports.
Refused to load the script 'https://www.googletagmanager.com/gtag/js?id=G-152WENDH2F' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Refused to load the script 'https://static.cloudflareinsights.com/beacon.min.js/v31edd6df95cf4e85bb4c19e7a9bdbcba1788362987495' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src
Refused to load the script 'https://www.googletagmanager.com/gtag/js?id=G-152WENDH2F' because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-inline'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
Your tracking has gaps — PayHelm can fix this.
Broken tags mean lost attribution and bad decisions. PayHelm unifies your ecommerce, ad, and analytics data so every number is trustworthy — no guesswork.