Go-Live Clearance

Methodology

How we decide CLEARED, HOLD, or DENIED.

Method version · Updated September 12, 2026

The scanner makes bounded HTTP requests to public URLs, follows at most five redirects, and evaluates the returned HTML, response headers, robots.txt, and sitemap signals. A pass means the tested signal was present at scan time; it is not a guarantee of indexing, security, accessibility, or legal compliance.

What does a GoLiveClearance result mean?

A result is a time-limited observation of the public response returned during one bounded scan. CLEARED means no configured blocker or warning was found in that response; HOLD means warnings remain; DENIED means at least one configured blocker was detected. The scanner does not crawl an entire site, sign in, execute every user journey, perform penetration testing, or predict search rankings. A later deployment, geographic response, bot-specific response, or unavailable resource can produce a different result.

Inspection Criteria

Every scan runs the following checks against your URL. Each finding is classified as a Blocker, Warning, or Pass based on its impact on your site going live.

BLOCKERhttps

HTTPS Encryption

Your site must serve over HTTPS. Plain HTTP exposes all visitor data to interception.

WARNINGhsts

Strict-Transport-Security (HSTS)

HSTS tells browsers to always use HTTPS, preventing first-visit downgrade attacks.

WARNINGx-content-type-options

X-Content-Type-Options

Prevents MIME-type sniffing that can lead to XSS via drive-by downloads.

WARNINGclickjacking

Clickjacking Protection

X-Frame-Options or CSP frame-ancestors prevents your site from being embedded in malicious iframes.

WARNINGreferrer-policy

Referrer-Policy

Controls how much URL information leaks to third-party sites via the Referer header.

BLOCKERrobots-txt

robots.txt — Full Block

A blanket Disallow: / prevents compliant crawlers from fetching the site. A known URL can still appear without a useful snippet, so robots.txt is not a removal mechanism.

WARNINGsitemap

XML Sitemap

A sitemap helps search engines discover all your pages. Missing sitemaps may cause incomplete indexing.

BLOCKERnoindex

Noindex Meta Tag

A noindex tag explicitly tells search engines to remove your page from results. The silent killer of launched sites.

WARNINGtitle

Page Title

Every page needs a descriptive title. Latin titles ideally 10–70 chars; short CJK brand names (e.g. 淘宝) are accepted.

WARNINGh1

H1 Heading

A visible H1 anchors the page topic for users and crawlers. Missing H1 is common on JS shells that forget semantic headings.

WARNINGdescription

Meta Description

A meta description (50-160 chars) controls your search result snippet. Without it, engines auto-generate often irrelevant text.

WARNINGcanonical

Canonical URL

A canonical tag prevents duplicate content issues from URL variants (www/non-www, trailing slashes).

WARNINGog-tags

Open Graph Tags

og:title, og:description, and og:image control how your site appears when shared on social media.

WARNINGfavicon

Favicon

Recognizes rel=icon, apple-touch-icon(-precomposed), and a valid /favicon.ico (including CDN redirects).

WARNINGsecurity-headers

Security Headers (merged)

HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are reported as one finding and ranked below launch accidents.

BLOCKERpreview-leak

Preview / Staging Domain Leak

Canonical, Open Graph, or sitemap pointing at *.vercel.app / *.netlify.app (or clearing a preview host as if it were production) sends crawlers and share cards to the wrong deploy.

WARNINGtrust-pages

Trust Pages

Privacy, Terms, and Contact links should exist on the homepage and resolve (not 404). Broken legal links kill trust on launch day.

WARNINGanalytics

Analytics

Detects GA4, Plausible, Vercel Analytics, Alibaba mmstat, Baidu Tongji, and other common snippets.

WARNINGplaceholder-copy

Placeholder Copy

Leftover lorem ipsum, TODO, yourdomain.com, or coming soon copy that makes the site look like a staging build.

WARNINGsitemap-dirty

Sitemap Quality

Detects missing sitemaps, soft-404 HTML error pages that return 200, empty <loc> lists, preview hosts inside sitemaps, and missing robots Sitemap: directives.

Severity Definitions

BLOCKER

Will cause immediate, visible damage if you ship. Your site won't be found, won't be secure, or won't work as intended. Must fix before launch.

WARNING

Won't break your launch, but will hurt SEO, security posture, or user experience. Should fix soon after launch.

PASS

Check passed. No action needed.

Clearance Decision

The clearance verdict has three stamps:

  • CLEARED (Ship It) — Zero blockers and zero warnings. Safe to launch.
  • !HOLD (Fix Then Ship) — No blockers, but warnings remain. Fix the top priorities before you promote the launch.
  • DENIED (Don't Ship) — One or more blockers found. Do not go live until they are cleared.

The score (0-100) is calculated as: 100 - (blockers × 25) - (warnings × 5)

Rules and primary references

Rules are intentionally conservative. Blockers are reserved for conditions that can prevent a public launch or search discovery; warnings identify material quality or defense-in-depth gaps. Results may change when the target deploys new code or returns different content to the scanner.

Search crawlers, AI search crawlers, and training crawlers

These are separate policy decisions. A site may allow Googlebot, Bingbot, OAI-SearchBot, ChatGPT-User, ClaudeBot, or PerplexityBot for discovery and answer retrieval while applying a different rule to model-training crawlers. GoLiveClearance currently detects only a complete robots.txt block; it does not certify that every named crawler is allowed or that a crawler will index or cite the page.

Aggregate benchmark publication policy

GoLiveClearance does not currently publish issue-frequency percentages. The aggregation code requires at least 100 distinct domains before any rate can be emitted, deduplicates repeated findings from the same domain, and outputs only a finding ID, affected-domain count, and percentage. Hostnames, full URLs, query strings, report tokens, IP addresses, and page content are excluded from the publication contract. Meeting this threshold reduces small-sample and identification risk; it does not by itself make a future sample representative of the web.