ecomhint

The Ecomhint audit crawler

If you saw Ecomhint in your logs, this page explains why we visited, what we loaded, and how to check that the requests really came from us.

Overview

Ecomhint is a conversion audit for online stores. An audit looks at a store the way a shopper does: the home page, a product page, a collection page and the cart, on desktop and on mobile. It then reports what makes buying harder than it needs to be.

To see those pages, the audit opens them in a real browser. That browser is the crawler this page describes. It is not a search engine and it does not collect data for training AI models.

When it visits

Every audit starts because a person asked for it. Someone typed the store's address into ecomhint.com or asked an AI assistant connected to their Ecomhint account to audit it. Usually that person runs the store or works on it.

There is no schedule. The crawler does not come back to a store by itself; it returns only when someone asks for a new audit.

What one audit loads

One audit covers one store and usually finishes within a few minutes. It:

  • reads robots.txt and the sitemap, plus at most four sitemaps it links to, to find a product and a collection page;
  • checks a capped sample of the links it finds there, a few at a time, to pick a product page that can be bought;
  • opens the home page, one product page, one collection page and the cart in the browser, repeats the home page and the product page at a phone screen size, and takes screenshots;
  • adds one product to the cart, the way a shopper would, to see the cart page.

Page speed is measured by Google PageSpeed Insights, so those requests come from Google, not from us. Across the whole service no more than three audits run at the same time, and a store gets one audit at a time.

How to recognize it

Requests to the audited store are signed with Web Bot Auth, an HTTP Message Signature (RFC 9421) made with an Ed25519 key. Each signed request carries three headers:

  • Signature-Agent: "https://ecomhint.com"
  • Signature-Input with tag="web-bot-auth" and the key id;
  • Signature, which covers the request's host and the Signature-Agent header.

The public key is published at https://ecomhint.com/.well-known/http-message-signatures-directory. A signature that verifies against that key came from Ecomhint. Only requests to the audited store are signed. Images, scripts and fonts from other hosts that the page loads are not.

The browser is Chromium and presents a regular Chrome user agent, because some stores serve automated clients a different page than shoppers see, and the audit has to see the page shoppers see. The signature is how we identify ourselves.

What it never does

  • It never places an order, enters payment details or submits a form other than add to cart.
  • It never signs in to a customer account.
  • It never crawls a whole store or follows links from page to page beyond the sample above.
  • It never solves or bypasses a CAPTCHA or a bot challenge. If a store challenges it, the audit stops and tells the person who asked that the store blocked it.
  • It never gets past a storefront password or a Basic Auth login unless the person who asked for the audit entered that password.

Questions and opting out

If the crawler caused a problem on your store, or you want us to stop auditing it, write to [email protected] with the store's domain. You can also keep blocking it with your firewall or bot protection: the audit respects the block and stops.