Full site audit following the analytics launch
A second pass over the whole site, now that there is a record of what people actually open.
The September pass in SC-21 was run blind — every page weighed the same because there was no way to know which ones anyone reached. Analytics changes what an audit can ask: the pages that get opened deserve the scrutiny, and a page nobody has ever landed on is worth a different conversation than a broken link.
Wait for enough data to be worth reading. An audit run on three days of traffic would be measuring the deploy.
Carry forward from SC-21
Two findings there were left open rather than fixed, and this pass should close them or record why not:
- The Kremlin citation is
http://and unreachable from this machine. It has not been shown to be broken and must not be treated as broken, and thehttp://must not be rewritten on the assumption thathttps://works. It needs opening from a connection that can reach the host. - Ticket pages carry no JSON-LD, while entry pages emit an
Articleblock. Inconsistent rather than wrong.
Finding 3 there — no security headers beyond HSTS — is now partly answered:
SC-27 put Referrer-Policy: no-referrer on /holocron. The site-wide case is
still open, along with X-Content-Type-Options, X-Frame-Options,
Permissions-Policy and CSP.
What analytics adds to the checklist
- Which pages are actually entered from search, and whether their titles and descriptions read like the thing someone clicked.
- Whether any page is being reached that should not be — the holocron shows as
/(private), so a count above what you can account for yourself is worth knowing about. - Real device and viewport spread, rather than an assumption about it.