Indexable writing
Guides a crawler can cite
Not a blog. Not a newsroom. Pages that match what the engine actually scores, so Google and answer engines have something other than the homepage slogan.
Configuration
- llms.txt that a model can actually walkHow to write llms.txt as a URL map, not a slogan. What SiteRune scores, what we refuse to invent, and why a 200 OK file can still fail the chapter.
- Robots.txt for GPTBot, ClaudeBot, and PerplexityBotHow a Disallow on AI crawlers silently zeros your citation share — and how SiteRune reads robots.txt without guessing.
- Security headers a crawler can see (not a pentest)HSTS, CSP, framing, cookie flags — the public configuration SiteRune scores. What we will not scan, and how we write nginx / Vercel / WordPress snippets.
- Organization schema that answer engines can groundNewsMediaOrganization counts. A logo and a sameAs list beat a slogan. SiteRune treats *Organization types as an entity — and refuses to invent one.
- The homepage is a liar. Audit the interior.Why SiteRune walks nav, sitemap, and llms.txt URLs instead of scoring a single lab URL like Lighthouse.
- GEO and AEO are configuration, not keyword densityGenerative Engine Optimization is whether an answer engine can ground a citation from your HTML. SiteRune scores that as its own chapter — not TF-IDF for ChatGPT.
- How to get cited by ChatGPT, Perplexity, and GeminiAnswer engines cite pages they can fetch and ground. Block GPTBot and you are invisible. Ship llms.txt, entity schema, and dated articles — then rescan.
- HSTS without locking yourself out of HTTP foreverStrict-Transport-Security is a high finding on SiteRune when it is missing. Preload is optional. includeSubDomains is not something to copy from a blog if you still have an HTTP tool on a subdomain.
- Cache-Control for HTML: s-maxage without caching the dashboardSiteRune flags no-store and private on the document as weak HTML caching. Public pages should be cacheable at the CDN. App shells and account pages should not.
- security.txt (RFC 9116) that a researcher can actually useA missing /.well-known/security.txt is an info finding on SiteRune. Info still costs a point. Ship Contact and Expires. Do not invent a bug-bounty program you do not run.
- The noindex that quietly deindexes a production siteStaging plugins, 'discourage search engines', and leftover robots meta on templates. SiteRune treats homepage noindex as critical and inner noindex on wordy URLs as high.
By CMS
- WordPress audit: cache, builders, and headers nginx actually setsHow SiteRune fingerprints WordPress, what the WordPress bootcamp playbook contains, and why page builders show up as CMS health — not as a moral failing.
- Shopify audit: app JS, images, and headers Shopify will not let you setSiteRune's Shopify fingerprint, Hydrogen vs Online Store, and why Cloudflare in front is in the playbook.
- Next.js audit: App Router, metadata, and headers()SiteRune fingerprints Next from /_next and runtime markers. The playbook treats it as a server. We skip the bootcamp speech on sites that are already elite.
- Webflow audit: headers you cannot set in the DesignerSiteRune fingerprints Webflow from data-wf-page and the runtime. CSP, HSTS, and frame-ancestors usually need Cloudflare in front. The playbook says that without a CDN essay.
- WooCommerce audit: product schema, not a cart crawlSiteRune fingerprints WooCommerce assets on WordPress. We skip cart and checkout. The brief is headers, cache, and JSON-LD Product — not a SKU indexer.
- Wix audit: headers the editor will never sendSiteRune fingerprints Wix from static.wixstatic.com and x-wix headers. CSP and HSTS almost always need Cloudflare in front. The HTML still has to contain words.
- Squarespace audit: templates, thin HTML, and a proxy for headersSquarespace fingerprints from sqs-block and their CDN. SiteRune will not invent a header UI Squarespace does not have. Cloudflare in front is the usual path.
- Drupal audit: cache bins, Twig, and headers at the vhostSiteRune fingerprints Drupal from generator tags, Drupal.settings, and /sites/default/files. The brief is reverse-proxy cache and modules — not a Drupal.org essay.
- Joomla audit: extensions, generator tags, and Apache headersJoomla fingerprints from generator and /media/jui/. SiteRune treats it as a PHP CMS: cache at the edge, headers at the vhost, stop shipping every extension on the homepage.
- Ghost audit: membership walls vs a citable publicationGhost fingerprints from generator and /ghost/api/. SiteRune scores the public HTML. Members-only posts we cannot fetch do not count as AEO coverage.
- Magento / Adobe Commerce: FPC, apps, and a crawl that skips checkoutSiteRune fingerprints Magento from static/version and mage cookies. TTFB is usually uncached PHP plus extensions. We do not index the catalog.
- BigCommerce audit: stencil apps and headers the control panel skipsSiteRune fingerprints cdn11.bigcommerce.com. Like Shopify, arbitrary security headers usually need a CDN in front. We skip cart.
- PrestaShop audit: modules, CCC, and nginx — not another sliderPrestaShop fingerprints from generator and asset paths. SiteRune wants edge cache, fewer modules on the homepage, and headers at the vhost.
- HubSpot CMS audit: tracking tax vs a site a crawler can quoteHubSpot fingerprints from hs-scripts.com and hs-banner. SiteRune scores the public page. Chat widgets and three HubSpot JS files are the usual third-party finding.
- Framer audit: canvas sites still need HTML a crawler can readSiteRune fingerprints Framer from framerusercontent and __framer. We fetch HTML, not the editor canvas. Headers are hosted-CMS limited.
- Nuxt audit: routeRules, Nitro, and headers that are not next.configSiteRune fingerprints __NUXT__ and /_nuxt/. The playbook is nuxt.config routeRules / nitro.routeRules, not a Next.js snippet.
- Gatsby audit: static HTML that still ships no-store and a fat runtimeSiteRune fingerprints ___gatsby. SSG should be the easy mode for TTFB. It often is not, because the host sends no-store or the page hydrates a SPA anyway.
- Astro audit: islands, adapters, and HTML that should already be thinAstro fingerprints from astro-island and the generator. SiteRune expects server-rendered HTML. Islands that hide the hero from the first response still fail.
- Remix audit: headers() on the document, not a SPA costumeSiteRune fingerprints __remixContext. Remix can send headers from the document request. The brief treats it as a server.
- SvelteKit audit: hooks.server, prerender, and a document cacheSiteRune fingerprints __sveltekit. Playbook: prerender public pages, set headers in hooks.server.js, do not turn the marketing site into a logged-in app.
- Docusaurus audit: docs are AEO gold if the HTML is actually thereDocusaurus fingerprints from generator and runtime strings. SiteRune wants indexable docs HTML, a sitemap, llms.txt that lists the real pages, and headers at the host.
- Contentful: we saw the CDN. The origin is still your framework.ctfassets.net is a fingerprint, not a CMS you configure in our UI. SiteRune still scores the Next/Nuxt/Astro (or unknown) origin that embeds Contentful.
- Sanity audit: cdn.sanity.io is a clue, GROQ is not the playbookSiteRune fingerprints Sanity's CDN. The ship files and header findings belong to the site that queries it — usually a JS framework or a custom origin.
- Strapi audit: the API is not the websiteA Strapi mention in HTML is a weak fingerprint. SiteRune scores the public frontend. Headers and llms.txt live there, not on /admin.
- Laravel audit: cookies, Livewire, and nginx in front of PHPSiteRune fingerprints laravel_session, XSRF-TOKEN, and Livewire. Marketing pages should not inherit the app's no-store session layout.
- Django audit: csrftoken on a marketing page is a smellSiteRune fingerprints Django cookies. The playbook is WhiteNoise or nginx for static, cache for anonymous HTML, headers at the proxy.
- Rails audit: Passenger, sessions, and a CDN in front of the appSiteRune fingerprints Rails sessions and Passenger. Public pages should be cacheable. Headers belong in nginx or config/nginx, not a layout helper only.
- TYPO3 audit: realurl leftovers, cache, and headers at the vhostSiteRune fingerprints TYPO3 from generator and HTML. Treat it as a serious PHP CMS: cache, fewer extensions on the home, nginx headers.
- Craft CMS audit: Twig, nginx, and templates that actually print wordsSiteRune fingerprints Craft from craftcms and CRAFT_CSRF. The brief is cache and templates — not a plugin mall.
- Duda audit: white-label hosted sites and the usual header wallSiteRune fingerprints Duda from dudamobile and dmRoot. Arbitrary headers need a proxy. HTML still has to contain the copy.
- Weebly audit: Square's hosted builder, same limitsWeebly fingerprints from their runtime strings. SiteRune will not pretend there is an .htaccess. Proxy for headers; publish real text.
- Blogger / Blogspot: a template, a custom domain, and almost no header UISiteRune fingerprints blogspot.com / blogger.com. Custom domains still miss HSTS unless a proxy sends it. AEO is possible if posts are public HTML.
- Shopify Hydrogen: Oxygen, RSC, not a theme app embedSiteRune fingerprints Hydrogen / Oxygen. We will not tell you to install a Online Store theme app. Headers and cache follow the host — often Oxygen, not always Vercel.
Versus
- SiteRune vs LighthouseLighthouse is a lab score of one URL in a synthetic browser. SiteRune is a crawler brief with CMS dialect and ship files. You probably want both. They are not substitutes.
- SiteRune vs Semrush (and other SEO suites)Semrush is a keyword and backlink suite. SiteRune is not a rank tracker. It will not sell you a PDF of the same four issues every Monday.
- SiteRune vs PageSpeed InsightsPageSpeed Insights is Lighthouse on a Google URL. SiteRune does not run Chrome. Use PSI for LCP/INP proof. Use SiteRune for headers, robots, schema, and the CMS playbook.
- SiteRune vs AhrefsAhrefs is backlinks, keywords, and site-explorer. SiteRune is not a rank tracker. It will not estimate referring domains. It will tell you GPTBot is banned.
- SiteRune vs Screaming FrogScreaming Frog is a desktop crawler that can eat a whole site. SiteRune is a hosted brief of a polite handful of URLs plus ship files. Not a substitute.
- SiteRune vs SitebulbSitebulb is a desktop audit with graphs. SiteRune is a hosted CMS dialect plus AI-search and ship files. You might want both. They are not the same CSV.
- SiteRune vs SecurityHeaders.com and Mozilla ObservatoryThose tools grade response headers. SiteRune grades headers too — then robots, schema, interior pages, and a CMS playbook. A+ headers and a banned GPTBot can both be true.
- SiteRune vs SSL LabsQualys SSL Labs grades the TLS handshake. SiteRune notes protocol when we can see it and scores HSTS on the document. Not a certificate auditor.
- SiteRune vs BuiltWith and WappalyzerThose extensions list technologies. SiteRune fingerprints a CMS to write a dialect — then scores the origin. A logo cloud is not a playbook.
- SiteRune vs GTmetrix and WebPageTestFilmstrip tools run a browser. SiteRune does not. Use them for LCP waterfalls. Use SiteRune for TTFB from this vantage point, cache headers, and the CMS punch list.
- SiteRune vs Google Search ConsoleSearch Console is Google's field report for your property. SiteRune is one vantage-point crawl plus files. We will not replace coverage charts or Core Web Vitals in CrUX.
- SiteRune vs Yoast, Rank Math, and in-CMS SEO pluginsYoast lives inside WordPress. SiteRune fetches the public origin. A green traffic light in the editor is not HSTS, and it is not an llms.txt.
- SiteRune vs a penetration testWe are not a pentest. We do not fuzz, brute-force, or ship exploits. If a vendor scores headers and then attaches a PoC, they are mixing jobs. We refuse the second job.
- SiteRune vs Surfer, Clearscope, and 'AI SEO' writersThose tools score keyword coverage in a draft. SiteRune scores whether an answer engine is allowed to fetch you and can ground an entity. NLP density is not GEO.
- SiteRune vs Botify, Oncrawl, and enterprise log crawlersEnterprise crawlers ingest logs and millions of URLs. SiteRune is a senior-engineer brief for a host you paste today. Different budget, different output.
59 pages. By CMS matches the fingerprints in the engine. Versus is the tools people confuse us with.