An audit that tells you something is broken when it is not costs you an afternoon and your trust. So when I find a check that was wrong, I fix it and I write it down here.
Each entry says what the check said, why that was wrong, and what it says now. Stores are not named. The dates are the dates of the fixes, taken from my code history, and every entry comes from a change recorded there. This list holds the mistakes I know about. It does not mean there are no others.
If you think a finding is wrong
Email hello@audittag.com with the address of the page and what you expected to see. I reply the same working day, Monday to Friday, UK time. Weekends wait until Monday. If you are right, I fix the check and add it here.
Findings in the free audit and the Fix Pack
Newest first.
A second H1 that only exists in hidden template markup
What it said
Every product page of a live store was told it had two H1 headings, and images in the same markup could be flagged for missing alt text.
Why that was wrong
A theme's quick-view markup sits inside a template element. Browsers never show it and Google never indexes it, so its copy of the product heading is not a second heading on the page.
What it says now
Headings and images inside a template element are left out of the audit.
Title length that counted the indent
What it said
A 56 character title could be flagged as cut off, because it was measured as 63 characters.
Why that was wrong
Shopify themes often break the title tag across lines. The indent was counted as characters, and it is not part of the words in the title.
What it says now
Whitespace inside the title collapses to one space before any length or duplicate check.
No analytics, for sites that use a tool that is not Google's
What it said
A site that measured visits with a privacy-first tool was told it had no analytics. Off Shopify it was told the site was collecting no measurement at all.
Why that was wrong
The tag reader only knew Google's tags and the Meta Pixel. One store was loading Cloudflare Web Analytics on every page and still got that warning.
What it says now
Cloudflare Web Analytics, Plausible, Fathom, Umami, Matomo, Microsoft Clarity, PostHog and Simple Analytics are named from their standard installs, and only where the page loads them. They are kept apart from Google analytics, so no GA4 finding changes.
www and the bare domain treated as two sites
What it said
Every page of a www store was flagged as "Canonical points to another domain", with the warning that this keeps the page out of Google. The same audit listed all 10 crawled pages as missing from a sitemap that names the bare domain.
Why that was wrong
The canonicals named the same site without the www. That does not keep a page out of Google. The host compare was too strict, and the crawler had also ignored sitemap and menu links written on the other version of the address.
What it says now
Hosts match after a leading www is dropped, and http against https no longer counts as a different site. A canonical that names the other version gives one site-level notice, which says Google will usually list the host named and how to make the two agree. A different domain, including another subdomain, is still a cross-domain warning. The crawler now reads links on the other version as part of the same site.
Critical used for things that do not stop a page ranking
What it said
A missing title, a missing meta description, a missing or empty H1, missing alt text on content images and invalid JSON-LD were all marked critical.
Why that was wrong
None of them stops a page ranking. Calling them critical made audits look more alarming than the findings were.
What it says now
Those are warnings. Critical is kept for a noindex, a robots.txt that blocks the site, content that only appears with JavaScript and a broken dataLayer purchase. Under the findings, a box lists five things other audits call urgent that this one leaves out on purpose, each with the reason.
GA4 called installed twice when the app copy sends no page views
What it said
The same GA4 ID in theme code and in an app pixel was always reported as installed twice, with every page view counted twice.
Why that was wrong
Two live stores showed it is false for apps whose settings leave page views out. One app switched every GA4 event off, and the other listed only a few named events.
What it says now
Each app entry records whether its GA4 copy sends page views. Shopify's Google & YouTube app always does, so the warning stays there. An app that leaves page views out gets a notice that the ID is set up in both places and only the app copy runs on checkout. An app whose settings say nothing gets a softer notice that GA4 may be installed twice.
A tag counted as theme code because its ID was named there
What it said
On one store, GA4 and Google Ads were reported as theme code that misses checkout.
Why that was wrong
Neither tag loaded there. Both IDs only appeared in a cookie banner's Google Consent Mode settings, and the store sent its tags from a custom pixel.
What it says now
In theme code an ID counts only when something loads it, such as the address of a gtag.js or gtm.js file, the container in Tag Manager's own snippet, or a gtag config call on a page that loads gtag.js or Tag Manager. Any other ID is kept as named but not loaded. It never produces a "does not run on checkout" finding, and an analytics ID named that way softens the missing analytics warning to a notice.
robots.txt reported missing when the store was rate limiting us
What it said
Six Shopify stores in one run were told "No robots.txt", and the Fix Pack offered to write one.
Why that was wrong
Shopify always serves a robots.txt. Those six were the ninth to fifteenth stores checked back to back, and Shopify answered the request with a 429, which means too many requests. The crawler treated any answer but a 200 as not found.
What it says now
A robots.txt counts as missing only on a 404, a 410 or an HTML 404 page served as a 200. A 429, a server error, a 403 or a failed request leaves no robots finding and adds a crawl note that the file could not be read.
A logo inside the H1 read as an empty heading
What it said
A homepage whose H1 wraps the logo was read as having an empty H1, and the advice was to keep the logo and demote the real headline.
Why that was wrong
Heading text ignored images. A screen reader and a search engine read an image as its alt text. The Fix Pack could also replace everything inside a logo H1 with generated words, so the logo disappeared from the page.
What it says now
Heading text reads an image as its alt. An image H1 with no alt is reported on its own. Where the site declares its name, the fix sets that name as the logo's alt and leaves every other byte as it was. The text fix refuses to replace a heading that holds an image.
Brand profile links in microdata or RDFa read as undeclared
What it said
A store whose theme declares its brand in microdata was told its social profiles were undeclared, and the Fix Pack skipped that fix.
Why that was wrong
The check read JSON-LD only. Microdata and RDFa are also ways of writing schema.org data that Google reads.
What it says now
Schema types and sameAs links are read from JSON-LD, microdata and RDFa. When a page has a microdata or RDFa Organization, missing profile links are added to that item in the same syntax.
A checkout warning that ignored how the tag was installed
What it said
Stores whose GA4 came only through a Shopify app were told GA4 was in their page source and so did not run on checkout.
Why that was wrong
The reader said a tag was present but not how it was installed. On Shopify, tags in the web pixel configuration run on checkout and theme code does not. A cookie app's code comment that quoted a Meta Pixel call could also be read as a second pixel.
What it says now
Each tag is recorded with its route, theme, app or custom, and a checkout finding is raised only for the route it describes. Comments in HTML and scripts are no longer read as code.
Product schema in microdata read as missing
What it said
A product wrapped in schema.org microdata, as older Shopify themes write it, was reported as "Product page has no Product schema".
Why that was wrong
The schema checks read JSON-LD only. The Fix Pack would also have generated a second Product on top of the one already there.
What it says now
Schema.org types on elements that carry itemscope count as present. Microdata quoted in body text, comments, scripts or text boxes does not count.
No Meta Pixel, for stores that use Shopify's Facebook & Instagram app
What it said
Stores using Shopify's Facebook & Instagram app were told they had no Meta Pixel.
Why that was wrong
The app runs its pixel in Shopify's web pixel sandbox, so the usual fbevents.js file and fbq init call never reach the page.
What it says now
The app's entry in the page's web pixel configuration is recognised. I checked the pattern against the public homepages of 20 Shopify stores first, and it matched each of the 7 that carried the app's entry and nothing else. The missing pixel finding on Shopify also says that Customer events and other app pixels may not show up.
Tags quoted in a guide read as installed tags
What it said
Pages that quote an example tag in their text were reported as having a Meta Pixel and Google Ads installed, and a page that mentioned Shopify paths made a site that is not on Shopify look like a Shopify store.
Why that was wrong
Words on a page are not an installed tag. I found it by auditing this site's own guides.
What it says now
Tracking presence reads only script and noscript content, and the Shopify and WordPress fingerprints read markup only, never text.
Wording on this site that ran ahead of the product
These are not findings, but they are the same kind of mistake, so they are on the list.
Guardrails claims that were not true
What it said
The site listed email alerts as part of Guardrails and named a second Meta Pixel check. The result page said Guardrails watches whether each tag fires.
Why that was wrong
At the time Guardrails could only post to a webhook. It had no second Meta Pixel check, and it reads the HTML your pages serve, so it cannot see whether a tag fires.
What it says now
The email alert bullets and the second Meta Pixel claim are gone. The result page says a test order is the only way to see whether a purchase fires.
Guardrails described as watching events fire
What it said
The homepage, the Guardrails page, the about page and the sample page said Guardrails watched events fire, checked consent against OneTrust and Cookiebot, blocked deploys on staging and sent alerts to Teams and PagerDuty.
Why that was wrong
None of that was built.
What it says now
Firing checks, consent checks, failing a build on staging and Conversions API cross-checks are listed as roadmap, and the Guardrails page says it reads the pages your site serves.
Guardrails alerts that were wrong
None yet. This list starts when the first customer alert goes out. Every alert email carries a reference and asks you to reply if it looks wrong, and a wrong one is added here.