Website optimization (site audit)
What the site audit scores, the fix prompt, and letting our crawler through.
What does the site audit score?#
It depends on what is being audited.
- A website gets the site audit, on the Website optimization page: five dimensions, positioning, conversion clarity, trust signals, paywall and pricing, and SEO basics.
- An App Store or Google Play listing gets a listing audit, on the Listing optimization page: eight dimensions, title with subtitle and keyword field, icon, screenshots and video preview, long description and promotional text, trust signals, localisation, technical health including update cadence and privacy labels, and monetisation transparency.
Either way each dimension is a table of individual checks, and each check carries the finding behind it.
A check is not a simple yes or no. It comes back as Pass, Partial or Fail, and it is scored out of its own maximum, so you will see results like 4 out of 6 rather than a tick or a cross. Partial means the check found the thing but not in a state that earns full marks, so those rows are usually the cheapest points to win back.
Why is my site audit scored out of 85 rather than 100?#
Because the audit dropped the checks it could not fairly judge on your site and redistributed the weights. The usual case is a pre-launch or waitlist page with no pricing and nothing transactional to score. The banner at the top of the audit names exactly which checks were excluded.
What is the "Copy fix prompt" button?#
It copies the fixes from your audit as a ready prompt for your AI builder. Paste it into Lovable, Cursor or Claude and it works through them. The prompt also contains a link to the full audit, so your builder can follow the detail rather than only the summary.
If pressing it shows "Couldn't copy the fix prompt. Try again.", nothing reached your clipboard. Press it once more, and if it keeps failing tell us here and we will send you the prompt directly.
That link opens without signing in to HeyCatch. So if you want a developer, a designer or a co-founder to read the audit, you do not have to share your account or export anything: paste them the prompt, or just the link inside it, and they can open the full report. There is no way to switch that link off afterwards, so anyone you send it to can keep opening it.
Does the site audit read pages that are rendered with JavaScript?#
Yes. The audit renders your page with JavaScript executed, so a client-rendered site is read as it actually appears rather than as an empty shell. The one case it cannot score is a page that resolves to a sign-in screen: the crawler reaches it, hits authentication and stops there, and the report says so.
If an older run scored your site very low with findings that read as though the page were blank, re-run it and compare the per-check results rather than only the totals.
My site blocks bots. How do I let your crawler through?#
A page we cannot reach comes back as "We couldn't open this link. Make sure the URL is correct and publicly accessible.", and bot protection is the usual reason for it.
Bot protection such as Cloudflare can challenge our crawler even when the site opens fine for you: the audit runs from our servers, with its own IP address and user agent. When that happens, all we can read is the block page, and the site audit and the Product brief come back empty. On Cloudflare the challenge can come from Bot Fight Mode, Super Bot Fight Mode, a WAF custom rule with a Managed Challenge or JS Challenge, a high Security Level or "I'm Under Attack" mode, or a rate limiting rule with a challenge action. Cloudflare's Security Events for the minute of the run show which one answered, and that is the setting to change.
The usual shape of this is a server that returns 403 to anything that does not look like a browser. The site opens perfectly well for you, which is why it looks from the outside as though the fault is ours.
Worth knowing alongside it: a project is built from one link, so the address the project was created with is the one we read. Neighbouring subdomains are not part of it, and if you need one of those read as well, that is a separate project.
If you added your website on Website optimization and that run was blocked, the page shows "The site audit failed. Please try again." and "Your site's Cloudflare bot protection blocked us.", with a Retry · 40 credits button. The screen always suggests turning off Bot Fight Mode, even when the challenge came from one of the other settings above. Your link is kept, so once you have changed the setting, press Retry rather than pasting the link again. The 40 credits of a failed attempt come back on their own.
If it still will not read after you have changed the setting and tried again, tell us in this chat.
Does the site audit look at my signup or onboarding flow?#
No. It scores your public page and it stops at the signup button, so an audit that says nothing about your onboarding never looked at it, and a re-run will not change that.
The part that does see the flow is Analytics. The dashboard summary and the recommended improvements are written from real sessions on your site, and the users table opens one person at a time with the full timeline of what they did and where they stopped.
A finding in my site audit is wrong. How do I edit or override it?#
You cannot, audit findings are read only. Quote the finding here if it does not match your site: findings are corrected on our side, not in the app. Do not change your site to satisfy a finding you already know is wrong.