SEO Audit + EU Compliance Risk
Pricing
from $10.00 / 1,000 page auditeds
SEO Audit + EU Compliance Risk
One real-browser visit per page: on-page SEO audit (12 checks, 0-100 score) plus EU compliance risk - cookies and trackers set before consent (24 rules), WCAG 2.1 AA markup errors, security headers, and the domain's SPF/DMARC and security.txt. One row per page, with lead signals.
Pricing
from $10.00 / 1,000 page auditeds
Rating
0.0
(0)
Developer
ReadyStack
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
21 hours ago
Last modified
Categories
Share
Give it a list of pages. Each page is opened once in a fresh real browser (no stored consent, nothing clicked), and one dataset row comes back with an on-page SEO audit and the EU compliance risk the same page carries: which cookies and trackers were already there before the visitor agreed to anything, which WCAG 2.1 AA markup errors it has, which security headers are missing, and whether its domain publishes SPF, DMARC and security.txt. Every finding names the rule and the text behind it.
Who it is for: SEO and web agencies that already sell site audits and want the compliance findings in the same report; lead-generation teams qualifying lists of company websites (the lead_signals column); site owners with EU visitors.
What one row gives you
| Layer | What is checked | Rule set (version, dated) | Basis |
|---|---|---|---|
| SEO | 12 on-page checks (17 finding types) and a 0-100 score: title, meta description, h1, canonical, meta robots / X-Robots-Tag noindex, viewport, Open Graph, JSON-LD, thin content, redirect chain, HTTPS, Sitemap line in robots.txt or /sitemap.xml | this actor | Google Search Central documentation; sitemaps.org; ogp.me |
| Cookies before consent | 24 pre-consent rules (Google Tag Manager, Meta pixel, Hotjar, Clarity, LinkedIn, TikTok, Google Fonts, YouTube and Maps embeds, chat widgets, session replay ...) over the rendered page and every request the browser made; cookies set before any click, third-party cookies, cookies past the 13-month cap, and the fine ceiling for France, Spain or Italy | consent-audit-eu 0.1.4 (24 rules, 2026-09-20) + pre-consent-cookie-audit-2026 1.0.1 (2026-09-21) | ePrivacy Directive art. 5(3); CNIL cookie recommendation; Spain LSSI art. 39; Italy Garante |
| Accessibility | 24 WCAG 2.1 AA markup checks over the rendered page (page language, alt text, frame titles, blocked zoom, icon-only links and buttons, click handlers the keyboard cannot reach, autocomplete on identity fields ...), each with its occurrence count | wcag21-aa-legal-baseline-audit 0.1.5 (24 rules, 2026-09-25) | WCAG 2.1 AA as named by EN 301 549 (European Accessibility Act, applies since 2025-06-28) |
| Security headers | 4 presence checks (HSTS, Content-Security-Policy, X-Content-Type-Options, frame protection) plus 28 rules for header lines that do nothing or open a hole (retired headers, bare CSP keywords, script-src * or data:) | security-headers-csp-lint 0.1.5 (28 rules, 2026-09-20) | OWASP Secure Headers Project; RFC 6797; W3C CSP Level 3 |
| Mail authentication (domain) | published SPF, DMARC (with tree walk) and optional DKIM records against 19 record rules, plus 3 presence rules (SPF, DMARC, DKIM) from bulk-sender-lint; once per domain per run | spf-dmarc-record-lint 1.1.4 (19 rules, 2026-09-20) | RFC 7208; RFC 9989/9990 (DMARCbis); Gmail, Yahoo and Outlook.com bulk-sender requirements |
| security.txt (domain) | /.well-known/security.txt fetched as RFC 9116 says a reader must and checked against 13 rules; a missing file is reported as info on an ordinary website | security-txt-cra-lint 1.0.6 (13 rules, 2026-09-20) | RFC 9116; EU Cyber Resilience Act Annex I Part II(5) where the CRA applies |
Columns worth knowing
summary: one line per page, ready for a spreadsheet.seo_score: 100 minus 12 per SEO error, 5 per SEO warning and 1 per SEO info finding (floor 0). It scores the SEO layer only.compliance_risk:highwhen trackers or tracker cookies were present before consent, or the domain receives mail without SPF or DMARC;mediumwhen another compliance layer has an error; otherwiselow. It is a triage label computed from the findings, not a legal assessment.lead_signals: short flags such astrackers_before_consent,no_dmarc,dmarc_not_enforced,accessibility_errors,no_hsts,seo_noindex,seo_no_sitemap, for filtering a list of sites.issues: every finding withlayer,rule_id,severity,message,basisand, where useful,evidence,occurrencesandfix. The dataset has a second view, All findings, with one finding per line.
Tips
- Sites show EU visitors a different banner and set different cookies. For an EU view, set the proxy to Apify Proxy with an EU country.
- Ten pages of the same site cost ten page events but only one DNS and security.txt lookup.
- The cookie layer does not click the banner. It reports what exists before any choice is made, which is the state the law regulates.
Real run (2026-09-25, from a US server, no proxy)
| Page | SEO score | Compliance risk | Cookies before consent | Tracker sources before consent | WCAG error rules | DMARC | Signals |
|---|---|---|---|---|---|---|---|
| https://www.bbc.com/ | 89 | high | 18 | 2 | 0 | published | trackers_before_consent, no_csp |
| https://www.lemonde.fr/ | 100 | medium | 9 | 0 | 0 | published | no_security_txt |
| https://www.spiegel.de/ | 95 | medium | 3 | 0 | 2 | published | accessibility_errors, no_security_txt |
Input
{"urls": ["https://www.bbc.com/","https://www.lemonde.fr/"],"domainChecks": true,"country": "France (CNIL)"}
Pricing
Pay per event: $0.01 per page audited (page-audited), plus Apify's small run-start fee. You pay only for pages that loaded. A page that fails to load, times out or answers HTTP 4xx/5xx comes back as a row with status: error and is not billed. The domain checks are included in the page price. If you set a maximum cost per run, the actor stops before it.
What it does not do
- Whether the banner has a reject-all button on the first layer, names every purpose, and actually stops trackers after a refusal (listed per row in
not_measured) - Keyboard and screen-reader testing: the accessibility layer reads markup only, so a clean result is not a WCAG conformance claim
- Page speed and Core Web Vitals
- Backlinks, rankings, keyword research and content quality
- Pages behind a login
Disclaimer
Automated check of what is publicly served, against the rule text cited in each finding. It is not legal advice and not a compliance certification.
Made by ReadyStack. Free web versions of each check: https://getreadystack.com/tools?ref=apify