Checklist
What to get right when you build a website
A practical checklist for a site that works, gets found and stays found: structure, speed, product markup, policies, accessibility, and what people forget until it is costly.
11 min read·Updated
This is the list we work through on every build, in the order the items matter. It is ordered by consequence rather than by effort: the things at the top can make everything below them pointless if you get them wrong.
Before you write a line of code
These are cheap now and expensive later. Every one of them is a decision that gets baked into hundreds of URLs.
Pick one hostname and stick to it
Decide between www and no-www, and between http and https, then redirect every other combination to the winner with a permanent redirect.
Four addresses serving the same page splits your credit four ways and confuses anything trying to cite you.
Design your URLs on purpose
Short, lowercase, hyphenated, no session identifiers, no dates you will regret. /products/leather-tote, not /p?id=4471.
URLs outlive redesigns. Changing them later means redirects forever, and every redirect leaks a little.
Decide what happens to removed products
A discontinued item should either stay up marked out of stock, or redirect to the closest replacement — not silently 404, and not bounce everyone to the home page.
Links and recommendations accumulate against product pages. Throwing that away is throwing away the only asset that compounds.
The structure machines read
Humans forgive a messy page. Everything else — search engines, AI assistants, screen readers, your own analytics — does not.
One h1 per page, describing that page
Then h2 and h3 in order, without skipping levels for visual reasons. Style with CSS, not by choosing a smaller heading tag.
Heading order is how anything that cannot see your layout works out what the page is about.
Machine-readable product facts on every product page
Name, description, image, price, currency and stock status, as structured data in the page head. Generate it from the same source as the visible page, never by hand.
Hand-written markup drifts. A price in your data that disagrees with the price on the page produces confident, wrong recommendations.
A canonical address on every page
State which address is the real one, especially where filters, sorts and tracking parameters produce variants.
Without it, one product with five filter combinations becomes five competing pages.
A published list of your pages
A sitemap, generated automatically, pointed to from your robots.txt.
Without one, new products are found only when something happens to follow a link to them.
Server-rendered content for anything that matters
Prices, descriptions and stock status should be in the HTML, not written in by a script after load.
Most things reading your site do not run JavaScript. If your price only exists after hydration, to them it does not exist.
Speed, and what it actually means
Not a number to chase for its own sake. Three specific things annoy real people on real phones.
Stop the layout jumping
Give every image and embed explicit width and height, and reserve space for anything that loads late — banners, cookie bars, review widgets.
A page that moves under someone’s thumb as they tap is the single most infuriating thing on mobile.
Serve images at the size they are displayed
Modern formats, responsive sources, lazy loading below the fold — but never lazy-load the main image at the top.
Images are almost always the largest thing on a product page and the easiest win.
Audit your third-party scripts twice a year
Chat widgets, heatmaps, three analytics tools, an abandoned A/B testing script from 2023. Delete what you do not read.
Third-party scripts are usually the slowest part of a site, and nobody owns them.
The pages people look for before buying
A shopper deciding whether to trust you checks these, and so does anything deciding whether to recommend you.
Returns and refunds, in plain language
How long they have, who pays postage, what condition the item must be in. Linked from every page, not buried in checkout.
"Can I send it back?" is the last question before buying. An unanswered one is an abandoned cart.
Delivery terms with actual numbers
Where you ship, what it costs, how long it takes. Ranges are fine; silence is not.
Unknown delivery cost is the most common reason a full cart is abandoned.
Privacy and terms that match what you do
Including what your analytics and marketing tools collect. Generated boilerplate is better than nothing, but only just.
These are a legal requirement in most places you sell, and a trust signal everywhere else.
A real way to contact a human
An address that reaches someone, answered within a day. A contact form that goes nowhere is worse than no form.
Unreachable stores get treated as risky, by shoppers and by anything ranking them.
Accessibility, which is not optional
Most of it is free if you do it while building, and expensive to retrofit. It also happens to fix a lot of machine-readability at the same time.
Every image has honest alt text
Describe what it shows. Decorative images get empty alt, not a keyword dump.
It is what a screen reader announces, and what anything that cannot see the image has to work with.
Everything works from a keyboard
Tab through your checkout without a mouse. If you get stuck in a modal or cannot see where focus is, that is a bug.
Keyboard traps make a site unusable for some people and are trivially fixable.
Text has enough contrast
Including placeholder text, disabled buttons and anything over a photograph.
Low-contrast grey-on-grey is unreadable in sunlight for everyone, not just people with low vision.
Forms have real labels
Placeholders are not labels — they disappear when someone starts typing, exactly when they are needed.
Unlabelled fields are the most common reason a checkout cannot be completed with assistive technology.
After launch
The things that quietly break and nobody notices for months.
Check your robots.txt the day you go live
Staging sites block everything. That block is the single most common launch mistake, and it is invisible from the front end.
A site nobody is allowed to read ranks nowhere and is recommended by nothing, no matter how good it is.
Set a calendar reminder to re-check quarterly
Theme updates, plugin changes and platform migrations all rewrite these files without telling you.
Everything on this list can be undone by someone else’s update.
Watch for certificate expiry
Automated renewal fails silently more often than anyone expects.
An expired certificate replaces your store with a browser warning.
Questions
- What is the single most common mistake?
- A robots.txt left over from staging that blocks everything. It is invisible from the front end, it survives redesigns, and it makes every other item on this list irrelevant.
- How often should I run through this?
- Fully at launch, then the post-launch section quarterly. Platform updates and plugin changes quietly undo things you fixed months ago.
- Does this apply to a small shop?
- More so. A large retailer survives a broken returns page on brand recognition alone. A small store is judged entirely on what it shows, which makes the cheap fixes on this list worth proportionally more.
If you would rather not do this yourself
Websthan builds and maintains sites for a living, and works through this exact list on every one. Message us and describe what you have got.

Websthan
Digital Identity Agency · Dhaka, Bangladesh