What an SEO audit can honestly tell you — and what it can't
On-page and technical facts come from a page's own HTML. Rankings, search volume and backlinks are always a paid estimate. Exactly where the line sits.
· 5 min read
Two completely different kinds of SEO fact
An SEO audit report usually presents everything on one screen with the same visual confidence, which makes it easy to miss that it is actually reporting two entirely different kinds of fact. One kind lives on the page itself: the title tag, the meta description, whether there is exactly one h1, whether images carry alt text, whether the canonical tag points where it should, whether the page has accidentally been marked noindex, whether headings skip a level. All of this is readable directly out of the HTML a browser — or any tool — fetches. No third party is required, and nobody's private database is being consulted.
The other kind describes the world outside the page: how many people search a given term each month, where the page currently sits in results for that term, who links to it from elsewhere on the web. None of this is written anywhere in the page's own markup, and no search engine publishes it for free to anyone who asks. Confusing these two kinds — treating a rank position with the same casual confidence as a missing alt tag — is where most SEO advice quietly stops being checkable.
What a genuinely free audit can check
A realistic list of what's answerable from a page's own HTML runs longer than most people expect. The obvious checks — title, meta description, h1, canonical, noindex, thin content — are joined by a set that's just as checkable but less commonly looked at: the page's lang attribute, whether heading levels skip in a way that breaks the outline a screen reader or a crawler would build, a canonical tag that points somewhere other than the page itself, mixed content served insecurely on an otherwise-https page, link text vague enough to tell a reader nothing ('click here'), Open Graph tags left incomplete, and hreflang entries that duplicate each other in a way that confuses which regional version is canonical.
Every one of these is answerable by fetching exactly one page and reading what's actually in it — no vendor bill, no monthly quota, and nothing stopping a business from re-checking it the day after a fix goes live rather than waiting for a billing cycle to reset. That immediacy is worth more than it sounds: catching a regression the day it happens, rather than the month a report happens to run, is the difference between a two-minute fix and a quarter of lost visibility.
What genuinely cannot be answered without buying data
Rank position, keyword search volume, keyword difficulty, a competitor's ranking keywords, a backlink index — none of these can be answered from a page's own HTML, and the reason is structural rather than a matter of a tool trying harder. Google does not operate a public rank-lookup API and does not publish search volume; every 'keyword difficulty' or 'domain authority' figure quoted anywhere is a private company's own estimate from its own crawl of the web, not a number any search engine hands out.
A backlink index works the same way — every one that exists is a vendor's own independent crawl, and building one at a scale that's actually useful is not free at any real business's budget, which is why every business offering this data charges for it. Quoting a rank position or a keyword-volume number without naming which paid vendor's estimate it is amounts to presenting someone else's private guess as settled fact, and the business reading the report has no way to know that's what happened unless the report says so.
The middle case: free, but not automatic
A smaller, genuinely useful category sits between these two extremes: data a search engine's own systems hold and will actually release for free — but only to the specific site's owner, and only after that owner grants consent. Search Console is the clearest example: real impressions, real clicks, real average position by query and by page, at no cost — but only for a property the owner has personally verified, and only after they connect it through OAuth. Nobody else can pull that data on the owner's behalf without going through that same consent step.
Core Web Vitals and page-speed data sit in a similar spot: free once a Google Cloud API key exists, but that key has to be created and configured by someone with the right access — it does not arrive automatically the way an on-page check does. Both of these are worth pursuing precisely because they're free and genuinely accurate, unlike the paid-vendor category — but they need a specific, deliberate setup step, not a subscription.
Why 'blocked on a credential' beats silence
The real damage most SEO products do isn't charging for paid data — paying a vendor for a genuine estimate is a legitimate business decision. It's blurring the line between the three categories above, so a business reading a report can't tell which numbers are checkable facts about its own page, which need a free credential nobody has connected yet, and which are a paid vendor's private estimate dressed up to look like settled fact. A single unlabeled number sitting in a report doesn't announce which bucket it came from.
The more useful design names the gap plainly instead of filling it with an invented figure to look complete. 'This needs a licensed SERP provider, not connected on this deployment' is a more honest and more useful sentence than a rank position nobody actually measured. Khoji's own list of what it doesn't do is built this way on purpose — every gap named alongside exactly what it's blocked on: a paid vendor for rank tracking, keyword volume and backlink data; a free-but-owner-consent-only Search Console or PageSpeed key for two more; and, for one gap specifically, nothing paid at all — internal linking suggestions needs a whole-site crawl this deployment simply hasn't built yet, no vendor required.
Reading someone else's audit with this in mind
Whether it's Khoji or any other tool producing the report, the useful habit is asking which of the three buckets a given number falls into before treating it as ground truth: an on-page fact checkable right now from the HTML, a free number that needs the owner's own consent to unlock, or a paid vendor's private estimate. A report that doesn't make this distinction anywhere is not necessarily lying, but it is asking to be trusted more than its own sourcing supports.
A single composite SEO score out of 100 is itself a small tell worth noticing: producing one requires blending several of these buckets together with weights the report rarely discloses. An audit built instead around separate error, warning and note counts — each one traceable back to the specific check that produced it — is a more honest shape for exactly the same underlying information, because nothing has to be hidden inside an average to arrive at it.
Common questions
Can a free SEO audit tell me where I rank on Google?
No honest one can. Google does not operate a public rank-lookup service, so any rank position quoted anywhere is a paid vendor's own estimate from its own tracking, not a number Google hands out. A tool claiming to show your rank for free is either using a vendor's data without disclosing the cost somewhere else, or presenting a guess.
Is keyword search volume free data anywhere?
No — Google does not publish search volume figures publicly. Every keyword-volume number quoted by any tool is a private estimate built from that company's own data sources, priced accordingly. Treat any volume figure as an estimate from a specific paid source, not a fact from Google itself.
What's the fastest way to tell if an audit result is checkable myself?
Ask whether it's describing something written directly in the page's HTML — a title tag, an alt attribute, a canonical link — or something about the outside world, like a rank or a competitor's backlinks. The first kind you can verify yourself by viewing source; the second kind depends entirely on trusting whichever data provider produced it.
Why would Search Console data be free but still not show up in most audits?
Because it requires the site owner's own verified property and their explicit OAuth consent — no third party can pull it on their behalf without that step. A generic audit tool run against a URL with no ownership connection to that account structurally cannot access it, free or not, which is different from the data not existing.
Related pages