v0.4.0 β OmniRank finds where your site contradicts itself π #29
bemoshiur
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
π v0.4.0 β OmniRank finds where your site contradicts itself
Most SEO defects need an opinion β is 58 characters really too long for a title? v0.4.0 goes after a different category: defects a site proves against itself, no opinion required. A canonical pointing at a page marked
noindex. A sitemap URL thatrobots.txtforbids crawling. Anhreflangalternate that can't be indexed. Every one of these is two files on the same site disagreeing with each other, so precision is the whole claim β and the whole reason this release exists.πͺ Five gates, one theme: self-contradiction
robots.txtdisallowshreflangalternate that's itself noindexedWe ran it against danluu.com as a real-world test and it caught something genuine: the post "In defense of simple architectures" self-canonicalises to
/simple-architectureβ no trailing s. That URL 404s.Not a style nitpick. Every ranking signal that page earned is nominally being handed to a URL that doesn't exist. No external database, no crawler API, no judgement call β just the page's own tag checked against the page it points at.
One honest caveat:
seo.robots-sitemap.disalloweddepends on Python's ownrobots.txtmatcher, and that matcher genuinely behaves differently across versions we support (CPython rewrote it for RFC 9309 in 3.14, with a partial backport in 3.13). Rather than guess, the gate runs a live behavioural probe and reportsmatcher-unsupportedwhen it can't be sure β a refusal, never a wrong answer.π‘οΈ A new
securitylayernosniff, CSP presence, Referrer-Policy. We report what's there and stay quiet about whether it's enough, because that's a threat-model question, not an SEO one. Mozilla Observatory already does this well; we didn't need to do it worse.<script src=http://...>on an https page is blocked outright βerror. An<img src=http://...>is silently upgraded first and only fails if no https version exists βwarning, because claiming it's broken would often just be false.error. It gives every page a live duplicate at a second URL and splits your canonical signal in half.π What review caught β and we'd rather tell you than bury it
Final review found the new scoring formula wasn't monotone. Each layer's budget now divides by how many gates that layer has (fairer than the old flat 100 points β a tiny
securitylayer used to floor unreasonably fast). But an early version of that change let harmless info-only findings widen the denominator for free, which means adding a header-missing notice could make a real error look less bad.Reproduced against
danluu.comwith the identicalmixed-content/https-redirecterrors present the whole time:securityscored 87 under the buggy code, and the correct67only after the fix. Same defects. Worse-looking headers, somehow inflating the score.Report.score()promises adding a finding can never raise a score β we now assert that with a 40,000-trial property test that fails against the old code within its first 400 trials.We're telling you this because a tool whose whole pitch is "we only report what's provable" has to hold its own scoring to the same bar, and this is what that actually looked like in review.
π The numbers
67 finding ids (up from 48), 42
--fail-ongate names (up from 28), 5 audited layers instead of 4. Full list, generated straight from the registry so it can't drift: Finding Reference.Still writes nothing β
omnirank fixpreviews diffs, no--writeflag exists yet. Auditing better is zero-risk; a richer audit is what earns the right to edit files later.π¬ Tell us
robots-sitemap,canonical-target, orhreflang-noindexflagged something that wasn't actually a contradiction, we want the URL and the reason. A false positive here is a bigger problem than a missed one.next-app-router,static,jekyllandhugoresolve today; everything else honestly reportsnonerather than guessing. Astro, Nuxt, SvelteKit, WordPress β say which you'd actually use.Full notes in the CHANGELOG Β· Docs Β· Wiki
All reactions