Mission Growth

AI SEO Audit Tools: What They Actually Check (and Miss)

Most AI SEO audit tools check robots.txt rules, not real AI crawler access. See what each check verifies, what none confirm, and how to read any finding.

An AI SEO audit as a grid of tiles: five carry green checkmarks and one sits empty, an open frame with nothing mounted in it
On this page

You ran a free AI SEO audit and got a score, plus a red flag next to "AI crawler access." Before you touch anything: that checkmark usually confirms a robots.txt rule reads correctly. It doesn't confirm that ChatGPT, Perplexity or any other AI system has been near your site.

That gap runs through nearly every audit tool marketed around AI. Semrush, Ahrefs, SEOptimer, SEO Site Checkup, WordLift, AIOSEO and the open source claude-seo.md project each run a real, comparable layer of classic technical checks. Most also bolt on an "AI visibility" or "agentic readiness" claim that none of them explains the method behind.

Learn to tell a verified rule from an unverified claim, and you'll get more from any free AI SEO audit tool than a reader who just trusts the score.

In this guide:

  • What AI SEO audit tools actually check, and where the checks stop being comparable
  • Why an "AI crawler allowed" checkmark isn't proof a crawler showed up
  • The llms.txt check that measures the wrong bot's traffic
  • A decision table for which findings to verify first
  • Why two tools score you differently, and when to recheck

What "AI SEO audit" tools actually check

An AI SEO audit tool runs the same core technical checks classic SEO tools always ran. On top of that, it adds a newer, thinner AI layer.

That AI layer ranges from a real, testable check, like JavaScript-rendering detection, to an undisclosed marketing claim like "AI visibility across 6 engines." Here's how the classic layer breaks down across the tools we looked at:

Check categoryWhat it verifiesStated by
Meta tags, headings, keywordsBasic on-page elements are present and formattedSemrush, AIOSEO
Site speed and Core Web VitalsPage-speed metrics against Google's thresholdsSemrush
BacklinksLink profile size and qualitySemrush
Technical and on-page issue countBroken links, duplicate content, crawl errors and similar faultsAhrefs (170+), Semrush One (140+), SEO Site Checkup (70+)
Structured data and schema validationMarkup against Google and Schema.org requirementsAhrefs (190+ requirements), WordLift
JavaScript rendering / CSR detectionWhether the page runs on a client-rendered frameworkWordLift (text-to-script ratio)
robots.txt and AI crawler directivesWhether the crawl rule is written correctlyWordLift, Ahrefs (own crawler only)
"AI visibility" / citation claimAn AI visibility or citation number, method undisclosedSemrush One, SEO Site Checkup, SEOptimer

The classic layer is well documented, and it's genuinely comparable by vendor:

  • Semrush covers on-page basics through its free SEO Checker: headings and meta data, how keywords are used, the backlink profile, social signals, mobile-friendliness, page speed and Core Web Vitals. Upgrade to Semrush One and the count grows to 140+ technical and on-page checks.
  • Ahrefs Site Audit reports 170+ technical and on-page issues, 250+ data points per URL through its Page and Link explorer, and 190+ Google and Schema.org validation requirements.
  • SEO Site Checkup states 70+ technical factors for the same kind of ground.
  • AIOSEO's Analyzer checks technical errors alongside schema, internal links, content quality, keyword usage and page metadata.

The AI layer doesn't hold up the same way:

  • Semrush One's "AI Search Health Monitoring" promises to catch problems that could hurt where your brand shows up across AI answers, without saying how it measures that.
  • SEO Site Checkup claims AI visibility across 6 engines, tracking brand mentions, citation frequency and sentiment, again with no stated method.
  • SEOptimer names "LLM accessibility, identity, and citability" as factors that matter, the same gap.
  • WordLift's Agentic AI Audit, a term it uses for checking whether a site's structured data and crawl directives suit autonomous AI agents, is the one exception with a testable check: it flags client-side rendering through a text-to-script ratio, alongside structured data and robots.txt directives for AI agent access. It hedges its own structured-data check, though, stating it "does not apply equally to every AI agent" and matters most "when the agent uses tools such as Google, Bing, enterprise search, or knowledge graph pipelines."
Bar chart comparing AI SEO audit check counts: Semrush One 140+, Ahrefs Site Audit 250+, SEO Site Checkup 70+.
The highest published check count among these audit tools is 3.57 times the lowest, and each vendor defines a ‘check’ differently.

Running any of these tools for free gets you the entire classic layer, whichever vendor you pick. It won't get you a verified test of real crawler access, a confirmed citation count, or an AI visibility number with a disclosed method.

For the classic audit process itself, in order, see the classic SEO audit process. For the full check list this post draws from, see the full AI SEO checklist, and for indexing-level technical checks, see the technical SEO checklist.

The verification gap: what none of them confirm

Every fetched audit tool tests whether your robots.txt rules and structured data are theoretically correct for an AI crawler.

None of the seven tests what an AI crawler's own user-agent actually receives, checks a server log for a real visit, or tells you which of several differently purposed bots a single finding covers.

That last part is easy to miss. AI crawlers serve three distinct, separately documented purposes, and a single "AI crawler allowed" finding never describes a whole platform:

  • Training crawlers collect content for model training. GPTBot is OpenAI's: it "is used to make our generative AI foundation models more useful and safe" and to "crawl content that may be used in training." ClaudeBot does the same job for Anthropic, "collecting web content that could potentially contribute to their training."
  • Search retrieval crawlers fetch pages to power citations and search results. OpenAI's OAI-SearchBot "is used to surface websites in search results in ChatGPT's search features." Anthropic's Claude-SearchBot "navigates the web to improve search result quality for users." Perplexity's PerplexityBot is "designed to surface and link websites in search results on Perplexity. It is not used to crawl content for AI foundation models."
  • User-invoked fetchers run when a person, not a crawl schedule, triggers the request. Perplexity's own documentation states that Perplexity-User "generally ignores robots.txt rules" since a user requested the fetch.
Matrix of six AI crawlers by organization and purpose: training, search retrieval or user-invoked, plus robots.txt behavior.
GPTBot, ClaudeBot and PerplexityBot each serve a different purpose, and only Perplexity-User, triggered by a real person, ignores robots.txt rules.

OpenAI's own crawler documentation states that GPTBot and OAI-SearchBot are controlled independently. A webmaster can allow OAI-SearchBot to appear in search results while disallowing GPTBot to keep crawled content out of training, exactly as OpenAI describes it.

That sounds like a clean binary choice, but it isn't. Allow both bots, and OpenAI states it "may use the results from just one crawl for both use cases to avoid duplicative crawling." A single logged fetch, or a single per-bot checkmark on an audit report, cannot be assigned to one purpose by inspection alone.

The opt-out side is just as partial. Opt a site out of OAI-SearchBot, and OpenAI states the site "will not be shown in ChatGPT search answers, though can still appear as navigational links."

No binary allow/block checkbox on any audit report captures that middle state. It's the thesis of this whole post in one example.

Here's what the gap looks like in a real, published finding. The open source audit tool claude-seo.md reports one of its checks as "GPTBot blocked in robots.txt (ChatGPT score: 48/100)."

Read alone, that line implies blocking GPTBot hurts your standing in ChatGPT. It doesn't, at least not for the reason implied. GPTBot governs training only; the crawler behind ChatGPT Search citations is the separate OAI-SearchBot, controlled by its own robots.txt line. The corrected read: check OAI-SearchBot's status on its own before you treat a GPTBot finding as a ChatGPT visibility problem.

A static check can't confirm rendering either. As of the last public measurement of this, Vercel's December 2024 analysis of AI crawler traffic, none of the major AI crawlers it tracked executed JavaScript. At the time, GPTBot logged 569M fetches a month across two large sites, Claude 370M and PerplexityBot 24.4M.

An audit tool's CSR-detection flag tells you your site runs on a client-rendered framework. It doesn't confirm what any of those crawlers did with it. For the render mechanism, a four-fix table and how to verify it yourself, see how AI crawlers handle JavaScript rendering. For the fuller breakdown this section only sketches, see what GPTBot and OAI-SearchBot each do.

The llms.txt check that doesn't mean what you think

llms.txt is a real, publishable file, and an audit tool's checkmark for it confirms only that the file exists, not that it affects AI visibility.

Among the small share of published llms.txt files that get any request at all, Ahrefs' June 2026 log study found SEO audit tools request the file far more often than AI training crawlers do, and 77% of the bots requesting it aren't AI tools at all.

Split those AI bots by what they are for and the number that matters shrinks fast. Every named AI bot together accounted for 19.5% of requests, across four kinds: AI agents and agentic infrastructure 10.5%, training crawlers 5.3%, AI assistants 2.5%, and AI retrieval bots, the ones that fetch a page to answer a live query and can cite it, 1.1%.

That 1.1% is the figure an "AI-ready" checkmark is quietly promising you. SEO audit tools, at 21.7%, requested the file roughly 19.7x as often as those retrieval bots (21.7% ÷ 1.1%), and 4.09x as often as training crawlers (21.7% ÷ 5.3%).

Ahrefs states its own boundary on this number: the composition covers only the roughly 3% of published files that got any request at all, about 1.1K domains and 22K requests. A fetch isn't a read, so treat every one of these figures as a ceiling on real llms.txt use rather than a precise measurement.

Most published files never get requested in the first place. That full adoption funnel and its downloadable dataset live in the llms.txt adoption and read-rate data; this post doesn't restate it as its own finding.

That's the real problem with folding an llms.txt check into an AI visibility audit. Presence is hygiene. It isn't a visibility lever: the checkmark your audit tool gives it usually means its own crawler read the file, and an actual AI system probably didn't.

If you haven't built one, how to build an llms.txt file covers the spec. Run check your own llms.txt to confirm it at least parses correctly.

Which findings to act on first, and which to leave alone

A vendor-neutral decision table sorts check categories into three buckets: trust as written, spot-verify, or ignore for now.

That's a different question from a ranked pick between vendors; the table below applies the entity-level facts above as a general framework, not a verdict on any one tool.

Here's the table, by category:

  • Classic technical and on-page checks (meta tags, speed, schema tags): A pass means the rule or metric is present and correctly formatted. Spot-check one flagged page by eye; low priority, trust it as written.
  • Structured data and schema markup: A pass means the markup validates against schema.org syntax. Run it through Google's Rich Results Test before you call it done; medium priority.
  • robots.txt and AI crawler directives: A pass means the written rule is syntactically correct, nothing more. Fetch the page with the crawler's own user-agent, or check your server logs for a real visit; high priority, verify before acting.
  • JavaScript rendering / CSR detection: A pass means the tool detected your framework, not that a crawler rendered the page. Confirm with a rendered-fetch test; high priority.
  • llms.txt presence: A pass means the file exists at /llms.txt, nothing more. Check server logs for real AI bot requests instead of relying on audit-crawler hits alone; low priority on its own.
  • "AI visibility" or citation score: A pass means an undisclosed method produced a number. Don't act on it alone. Corroborate with a real prompt panel or a platform that verifiably tracks citations; highest priority, verify before acting.
Decision checklist matching six audit-finding categories to a verification step and a priority level.
A robots.txt or schema check passing means the rule is correct, not that an AI crawler acted on it; verify the highest-priority categories with a live test before trusting the finding.

A tool marketed around AI is reliable for the classic technical and on-page layer, and unreliable, unverified marketing for the AI visibility layer. A manual technical audit, or a platform built to run one, still catches what none of the seven vendor pages test for: real crawler behavior.

Mission Growth's platform tracks AI citations and visibility for customers.

Picking which tool to run for an LLM SEO audit is a separate question from reading the report you already have open. Which LLM SEO tool to buy covers the ranked category breakdown, or see the best ai search optimization tools for your category. To run the audit process this decision table sits on top of, run the audit order yourself.

Why two audit tools score you differently, and how often to recheck

A 0-100 audit score is a composite index: each vendor's own weighted mix of checks.

Ahrefs builds its number from 250+ data points, Semrush One from 140+ checks, SEO Site Checkup from 70+ factors: a spread of roughly 3.57x between the highest and lowest count in this set (250 ÷ 70). Two vendors' absolute scores were never built to be interchangeable.

So stop comparing tool to tool. Track one tool's own score as a trend instead.

AI LLM SEO audits split into two halves that belong on different cadences. Run the classic technical checks on your usual monthly-to-weekly schedule, and re-check the AI ones whenever something actually changes: crawler access, llms.txt, structured data. A robots.txt edit, a new bot rollout, a platform documentation update: any of those is a better trigger than a fixed calendar date alone.

Timing matters too. After you fix a robots.txt directive, OpenAI states a change can take about 24 hours to reach its search index for OAI-SearchBot, so a re-check run minutes after the fix can still show the old finding. That's one vendor's stated figure for one engine, not a general rule for every AI crawler.

When it's time to recheck, re-run the AI SEO checklist rather than eyeballing a single score.

An "AI SEO audit" tool's checkmark usually means a rule exists, not that an AI system has been confirmed to read, cite or act on your site. Read the classic layer as reliable and the AI layer as a claim to verify, and you'll get more from any tool's free report than a reader who just trusts the number.

Next time a scan finishes, don't fix findings in score order. Pull up the decision table above, verify the high-priority rows with a real crawler-UA fetch or a log check, and only then start changing robots.txt lines.

Frequently asked questions

Each vendor's score is a composite index built from its own weighted mix of checks, 70+ to 250+ in the tools covered here, so absolute scores from different tools aren't interchangeable. Track one tool's score as a trend instead of comparing it to another vendor's number.

No. In the tools covered here, only one tests rendered content at all, and none tests with the crawler's own user-agent or checks a server log. Most check whether your robots.txt rule is written correctly, which is a different thing from confirming a visit happened.

Not measurably. Among the small share of published llms.txt files that get any request at all, Ahrefs' June 2026 study found SEO audit tools request the file about four times as often as AI training crawlers do, and 77% of requesting bots aren't AI tools at all.

Not by itself. GPTBot collects training data; the crawler behind ChatGPT Search results and citations is the separate OAI-SearchBot, and OpenAI's own robots.txt settings for the two are independent. Check the finding bot by bot before you treat it as a platform-wide problem.

Re-run the classic technical checks on your usual monthly-to-weekly cadence. Re-check the AI-specific ones whenever something actually changes: a robots.txt edit, a new bot rollout, a documentation update. Then give a robots.txt fix time, because OpenAI states a change can take about 24 hours to reach its search index for OAI-SearchBot.

For the classic technical and on-page layer, an automated tool covers the same ground a manual audit would, faster. For the AI-visibility layer, none of the tools in this set discloses a verified measurement method, so a real citation check or a crawler-UA log test still needs a manual step.

Figures and images in this post are free to reuse under CC BY 4.0 with credit to Mission Growth.

Get Mission Growth highlighted in your Google results.

Related

Next step

Put these playbooks to work

Start with a free audit. See where the lift is before you commit.

How it works

  1. 01

    30-minute audit call

    We map your funnel against your goal and pull live data from your channels.

  2. 02

    Lift estimate

    You get a written estimate of where the lift is, with a 30-day plan to capture it.

  3. 03

    You decide

    Run it with us, run it in-house, or shelve it. No commitment from the audit.

We use cookies to keep the site running. Read our policy.

Strictly necessary

Authentication and core platform. Always on.

Analytics

Anonymised product usage via PostHog. Form fields are masked.