A proper site audit needs data analysis, code validation, and research, and none of that requires a paid SEO subscription to get started. Plenty of free tools match what their paid counterparts offer for a basic audit. The trick is knowing which tool answers which question, rather than opening ten tabs and hoping something useful turns up.
Most site owners discover this list piecemeal, one tool at a time, usually after Googling a specific symptom, a broken link report, a slow page, a security scare. Having the full set organized upfront saves that scattered discovery process and turns an audit into something you can actually run start to finish in one sitting rather than across a dozen separate searches spread over a week.
Below is a working list organized by what each tool actually diagnoses: content and keywords first, then the technical crawl layer, mobile, DNS and email deliverability, security, and finally performance. Run through them in roughly that order and you’ll have covered the ground a paid audit tool charges for.
One caveat worth stating upfront: free tools tend to cap output somewhere, a URL limit, a query limit, a report you can’t export past a certain size. That’s the actual tradeoff versus a paid subscription, not missing functionality so much as missing scale. For most site audits that ceiling never gets close to mattering.
Content and Keyword Tools
1. SEO Ngram Tool
SEO Ngram Tool analyzes word-combination frequency and patterns (n-grams) in content, useful for spotting keyword trends and repetition patterns across a site. If a page reads slightly off and you can’t pin down why, running it through an n-gram check often surfaces the repeated phrase pattern that’s dragging the copy down.
2. Answer The Public
Answer The Public visualizes the actual questions people search around a keyword, as a web/cloud diagram, useful for finding content gaps rather than just keyword volume. It’s less about ranking a specific term and more about noticing the exact phrasing of a question your content hasn’t answered yet.
3. Ahrefs Free Keyword Tool
Ahrefs Free Keyword Tool gives search volume and keyword difficulty for a given term, a scaled-down version of Ahrefs’ paid keyword explorer. It won’t replace a full keyword research workflow, but for a quick sanity check on whether a target term is worth chasing, it’s fast and accurate enough.
4. Siteliner
Siteliner scans for duplicate content, broken links, and internal linking structure across a whole site, not just single pages. Sites that have republished or lightly reworked old posts over the years tend to accumulate duplicate-content issues without anyone noticing, and Siteliner is one of the few free tools that catches it at the site level rather than page by page.
Technical Crawl Tools
5. W3C Validator
The W3C Markup Validation Service checks HTML against web standards and flags markup errors that can affect rendering and accessibility. Most sites carry a handful of minor validation errors that don’t break anything visibly, but a validator run occasionally catches something that’s quietly interfering with how a page renders in an older browser or an accessibility tool.
6. Screaming Frog
Screaming Frog crawls a site and reports on titles, meta descriptions, headings, broken links, and duplicate content, still the closest thing to an industry-standard technical crawler. The free tier caps at 500 URLs, which covers most small-to-mid sized sites for a full technical crawl without paying for the desktop license.
7. Netpeak Spider
Netpeak Spider covers similar ground to Screaming Frog, broken links, duplicate content, meta tags, page speed, a reasonable alternative if you want to compare crawlers or prefer its interface. Running the same site through both occasionally turns up something one missed that the other caught.
8. Xenu Link Sleuth
Xenu’s Link Sleuth checks for broken links and missing images. Worth flagging honestly: development on Xenu has been dormant for years, it still runs and does the basic job, but don’t expect active updates or support if something breaks. Treat it as a lightweight backup check rather than your primary link auditor.
Mobile SEO
9. MobileMoxie
MobileMoxie focuses specifically on mobile search: a Mobile SERP Test Tool, mobile page-click analysis, and mobile rank tracking. It’s worth a look specifically because most general-purpose SEO tools still treat mobile as an afterthought, and mobile is where the majority of search traffic actually happens now.
Technical Audit Tools
10. DNS Propagation Checker
whatsmydns.net shows whether DNS changes have propagated across servers worldwide, useful right after a migration or DNS update. If a site’s been unreachable in one region but fine in another after a domain or hosting change, this is the first place to check before assuming something’s actually broken.
11. MX Toolbox Blacklist Check
MX Toolbox Blacklist Check checks whether a domain or IP has landed on an email blacklist, relevant if transactional or marketing emails are landing in spam. It’s an easy thing to overlook during a content-focused SEO audit, but a blacklisted domain quietly kills conversion emails, password resets, and anything else riding on that same sending reputation.
Security Audit Tools
12. WPScan
WPScan is a WordPress-specific vulnerability scanner, checks core, plugins, and themes against a known vulnerability database. Search visibility and site security aren’t unrelated concerns: a compromised site gets flagged and delisted fast, so a security pass belongs in any audit that’s actually trying to protect rankings, not just improve them.
13. SSL Labs Security Checker
Qualys’s SSL Labs grades your SSL/TLS certificate configuration and flags weak ciphers or misconfigurations most site owners wouldn’t catch manually. A grade lower than expected usually traces back to an outdated server configuration that predates the current certificate, worth fixing since browsers increasingly flag weak configurations to visitors directly.
14. Hacker Target Drupal Security Scanner
The Drupal Security Scanner is the Drupal-specific equivalent of WPScan, relevant if you’re auditing a Drupal site rather than WordPress. Worth keeping in the toolkit if you manage or audit sites across multiple CMS platforms rather than WordPress exclusively.
Performance Tools
15. GZip Compression Checker
GZip Compression Checker confirms whether a server is actually compressing responses, a quick win for load time if it isn’t. It takes about ten seconds to run and, on the sites where compression is off, fixing it is usually a one-line server config change with an immediate, measurable payload reduction.
16. YSlow
YSlow, originally from Yahoo, audits page speed and gives optimization recommendations. Worth noting: Yahoo no longer actively promotes or develops it, and the ecosystem has largely moved to Lighthouse and PageSpeed Insights for this job, so treat it as a secondary check rather than a primary one.
17. GTmetrix
GTmetrix remains one of the more detailed free performance analyzers, waterfall charts, load time breakdowns, and specific optimization suggestions. The waterfall view in particular is worth studying closely; it’s usually where you spot the one oversized asset or blocking script that’s dragging the whole page down.
Free Google Tools
Google’s own tools round out the stack, and none of them cost anything.
- Google Search Console: indexing status, keyword performance, click-through rates, mobile usability, and crawl errors, all from Google’s own data.
- Google PageSpeed Insights: site speed analysis and optimization suggestions, both mobile and desktop.
- Google Analytics: traffic and behavior data that’s genuinely useful for content and structure decisions, not just vanity metrics.
- Google Mobile-Friendly Test: flags whether a page passes Google’s mobile-usability bar.
- Rich Results Test: Google retired the old Structured Data Testing Tool and migrated non-Google-specific validation to the separate Schema Markup Validator. Use Rich Results Test for how Google specifically will render your markup, and Schema Markup Validator for general schema.org compliance.
- Lighthouse: built into Chrome DevTools now rather than a separate extension, audits performance, accessibility, best practices, SEO, and PWA compliance in one pass.
How to Sequence an Audit With These Tools
Running seventeen tools in no particular order wastes time and produces overlapping, sometimes contradictory findings. A tighter sequence works better.
Start with a full-site crawl using Screaming Frog or Netpeak Spider. That single pass surfaces broken links, missing meta descriptions, duplicate titles, and thin pages in one report, and everything after this step is really just following up on what the crawl flagged.
Cross-check duplicate content with Siteliner, since crawlers catch technical duplication but miss near-duplicate content that reads differently but covers the same ground. Then move into Search Console for the indexing and click-through data no third-party tool can replicate, since it’s coming directly from Google’s own index.
Performance and security come last, not because they matter less, but because there’s no point optimizing load time on a page you’re about to restructure based on what the crawl and content review turned up. Run GTmetrix and Lighthouse once the content and structure decisions are locked in, then close with WPScan or the Drupal scanner and an SSL Labs check as a final security pass.
Mobile and DNS checks fit in whenever they’re relevant rather than on a fixed spot in the sequence. Run the Mobile-Friendly Test alongside the crawl if mobile traffic is a meaningful share of the audience, which for most sites in 2026 it is. Save the DNS and blacklist checks for right after any hosting, domain, or email provider change, since that’s the specific moment those issues actually surface, and running them at any other time mostly just confirms nothing’s wrong.
Where free tools genuinely fall short
Worth being honest about the gap rather than pretending it doesn’t exist. Free tools handle the diagnostic side of an audit well: what’s broken, what’s missing, what’s duplicated. What they don’t handle well is longitudinal tracking across dozens or hundreds of pages over months, the kind of trend line that shows whether a fix actually moved the needle three months later.
Rank tracking at scale is the clearest example. Screaming Frog’s free tier caps at 500 URLs per crawl, which is plenty for a single audit but becomes a real limitation on a large site you’re auditing repeatedly. Paid tools also tend to bundle competitor comparison data, so you can see not just your own site’s gaps but where a competitor is winning the same keywords. None of the free tools above do that natively.
For a one-off audit or a small site maintained by one or two people, none of this matters much. The gap shows up once you’re managing audit cycles across many sites, or need historical data going back further than a manual export lets you keep.
Turning this into a repeatable checklist
A one-time audit finds problems. A repeatable process catches them before they compound. Once you’ve run through the tools above the first time, the second pass gets faster if you write down what you actually checked and in what order.
A simple version: crawl monthly with Screaming Frog and diff the results against the previous month’s export, watching specifically for new broken links or newly-duplicated titles rather than re-reviewing everything from scratch. Check Search Console weekly for new crawl errors, since those tend to surface faster there than anywhere else. Run a security scan quarterly unless the site’s had a recent plugin or theme change, in which case run it immediately after.
Performance checks are worth doing after any significant content or template change, not on a fixed calendar, since that’s when load time actually shifts. Building even this loose a cadence turns the tool list above from a one-time exercise into something closer to ongoing site health monitoring, without paying for a monitoring platform to do it.
Which tools matter most by site type
Not every site needs the full seventeen-tool pass. A five-page brochure site and a five-thousand-page ecommerce catalog have different failure modes, and the audit should reflect that.
A small content or brochure site gets most of its value from the content and technical crawl tools near the top of this list: Siteliner for duplication, Screaming Frog for the broken-link and meta-description sweep, and Search Console for what Google’s actually seeing. Security and DNS tools matter less here simply because there’s less surface area and less traffic riding on uptime.
An ecommerce catalog needs the crawl tools run more aggressively, since duplicate product descriptions and thin category pages are the most common issue at scale, and Screaming Frog’s export makes it easy to filter for pages under a certain word count. Performance tools matter more here too, since checkout and product page load time have a direct line to revenue in a way a blog post’s load time doesn’t.
A SaaS or membership site with a login-gated area needs the security tools weighted heavier than the rest. WPScan and SSL Labs deserve a spot in the regular rotation, not just the one-time audit, because that’s the part of the site an attacker actually wants access to.
Free Covers the Fundamentals
None of these tools alone replaces a full audit. Realistically, a proper audit means combining a crawler (Screaming Frog or Netpeak Spider) with Google’s own tools (Search Console, PageSpeed Insights, Rich Results Test) plus a security scan if the site handles any sensitive data. Free covers the fundamentals; paid tools mostly add scale and automation on top, which starts to matter once you’re auditing dozens of sites rather than one.
For a single site audit, or even a handful, there’s genuinely no gap this list leaves uncovered. Save the paid subscriptions for when manual tool-switching itself becomes the bottleneck.
Questions that come up mid-audit
How long should a full audit with this tool stack actually take?
For a site under fifty pages, budget half a day: an hour or two for the crawl and duplicate-content check, another hour reviewing Search Console, and the rest split across performance and security. Larger sites take proportionally longer mostly because reviewing crawl output, not running the crawl itself, is where time actually goes.
What if two tools disagree with each other?
It happens more often than you’d expect, especially between different crawlers or between a crawler and Search Console. Search Console wins when the disagreement is about indexing or how Google specifically sees a page, since that’s first-party data. For everything else, mixed and re-check signals point to something genuinely ambiguous, like a page that’s borderline thin content rather than clearly thin, and that’s worth a manual look rather than trusting either tool blindly.
Is it worth running the same audit on a schedule, or only when something feels wrong?
Waiting for something to feel wrong means you’re already behind. A quarterly pass with the core tools, crawl, Search Console, one performance check, catches drift before a site owner notices something’s off. The tools listed here are free precisely because running them repeatedly costs nothing but time, so there’s little reason not to build them into a standing calendar reminder.
Do these tools work the same way for a non-WordPress site?
Mostly yes. The crawlers, Google tools, performance testers, and general security scanners (SSL Labs, MX Toolbox) are platform-agnostic. WPScan is WordPress-specific and the Drupal scanner covers that one platform; for any other CMS, swap in that platform’s equivalent vulnerability database if one exists, or lean more heavily on the general crawl and performance tools instead.