Ninety percent of "SEO audits" boil down to the same foundation: valid HTTPS, one canonical version of your site, crawlable pages and fast loads. Do this before spending a dollar on anything else.
Browsers flag plain-HTTP pages as "Not secure" and Google uses HTTPS as a (small) ranking signal. Let's Encrypt certificates are free and renew themselves — on WebDeps they're provisioned automatically at setup. If you manage your own server, Certbot plus a cron job does the same.
Pick https + one host (we recommend the bare domain) and 301-redirect everything else there. Four versions of the same page splits your ranking power four ways:
server {
listen 80;
server_name example.com www.example.com;
return 301 https://example.com$request_uri;
}
After moving to HTTPS, search your HTML for http:// — one insecure image or script keeps the padlock broken. Fix the URLs at the source (or in the database), don't paper over it.
A sitemap.xml listing your real pages (submitted in Search Console) plus a robots.txt that doesn't accidentally block CSS/JS. Then check Search Console's coverage report monthly — "crawled, not indexed" on important pages means thin content, not a technical curse.
Every page: one H1 matching the topic, a title under ~60 characters people would click, and a meta description that sells the click (it doesn't rank you, but it wins the click). This page you're reading follows exactly that.
LCP under ~2.5s (see our speed guide), no layout jumps while loading (reserve image space), and pages that respond to taps quickly. Perfect scores aren't required — beating your actual competitors is.
Meta keywords (dead for 15+ years), keyword-stuffed footers, and anyone selling "1,000 backlinks for $5" — the last one can get you penalized. Content people link to on purpose beats all of it.
Free auto-renewing SSL, forced HTTPS, sitemap-ready hosting and speed tuning come standard on every plan. See plans →