Engineering & Audit Methodology
1. Technical Visibility Audit Architecture
Our SEO & AI Visibility Checker runs on a dedicated Node.js serverless API runtime with a strict 30-second execution window. Every input URL is normalized to enforce HTTP/HTTPS protocols and passed through an SSRF (Server-Side Request Forgery) protection layer.
- DNS Resolution via Node.js
dns.promises.lookup - Blocking of Private/Loopback/Link-Local IPv4 & IPv6 ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, ::1/128, fe80::/10)
- Port restriction to standard HTTP (80) and HTTPS (443)
- Strict 8-second request timeout with max 5 manual HTTP redirect follows
- Maximum payload parsing cap of 2MB to prevent memory exhaustion
2. Parallel Inspection Engine
Audits execute 5 parallel check vectors using Promise.allSettled:
- robots.txt Crawler Rules: Parses User-Agent directives for Googlebot, Bingbot, OAI-SearchBot, GPTBot, PerplexityBot, and ClaudeBot.
- llms.txt Machine Discovery: Checks domain root for AI training and index discovery files.
- XML Sitemap Health: Verifies sitemap availability and canonical directive alignment.
- JSON-LD Schema Syntax: Extracts and parses embedded
application/ld+jsonblocks, checking for valid JSON structure and required Schema.org fields. - On-Page Technical Signals: Measures single H1 presence, meta title length (≤60 chars), meta description length (120–160 chars), and self-referencing canonical tag matching.
3. Canvas SERP Pixel Width Measurement
Rather than relying solely on character counts, our SERP Preview tool utilizes HTML5 Canvas 2D context measuring (Arial 20px for Google desktop titles) to accurately project truncation boundaries at 580px for titles and 920px for descriptions.
4. Keyword Opportunity Scoring Formula
Keyword opportunity scores (0–100) use a transparent, deterministic mathematical formula:
"Strong Opportunity" badges are rendered only when metrics are supplied directly from verified provider data (DataForSEO) or official APIs—never fabricated.