Inside the $0.50 free audit
How the site is fetched, what the AI actually sees, what the human edits, and why I personally read the first twenty reports.
Qaynaq’s lead magnet is free. Building something that’s free isn’t actually easy — you still owe the partner real work. Here are the technical steps, the cost structure, and the decision points, in the open.
The pipeline has two halves
Half 1 — mechanical findings
The moment a partner submits the form:
- Playwright (stealth) fetches the site — residential IP, real User-Agent, normal navigation pattern, so Cloudflare doesn’t filter the request.
- Lighthouse and axe-core pull the mechanical metrics — performance, SEO headers, contrast, keyboard navigation, ARIA errors.
- HTML, header, and robots.txt analysis — CSP, HSTS, meta tags, structured data, sitemap.
- Outdated dependency scan — script src attributes get parsed for old Bootstrap, jQuery, double-mounted GTM, the usual suspects.
This half doesn’t touch AI. Every finding has a precise source.
Half 2 — synthesis
Now we hand three contexts to the Claude API:
- The structured output of Half 1, as JSON.
- Quoted HTML fragments from the site (only the relevant chunks).
- The partner’s business category — e-commerce, corporate, agency, etc.
The LLM returns structured JSON, not prose. This matters: the PDF template fills field by field from that JSON. A hallucination can’t poison the whole report because every finding without a source is dropped.
Models in use:
| Step | Model | Why |
|---|---|---|
| Extraction | Haiku 4.5 | Fast, cheap, simple format |
| Synthesis | Sonnet 4.6 | Strong prose, sound judgment |
| Risk scoring | Sonnet 4.6 | Lower hallucination on the rating axis |
Prompt cache is on. A repeat audit on the same site is roughly 30% cheaper.
Cost per report
Average marginal cost:
- Playwright fetch + Lighthouse: ~$0.05 (CPU time)
- Claude API: ~$0.40
- PDF rendering: ~$0.02
- Email send (Resend): ~$0.001
- Storage (Supabase): ~$0.005
Total: ~$0.48 per report.
Even with a 2% conversion to a paid engagement, the lead magnet pays for itself many times over.
”Can’t AI just do the whole thing?”
Answer: no. And we don’t hide the limit.
What AI does well here:
- Mechanical surfaces — header staleness, performance bottlenecks, SEO structure issues.
- Synthesis — collapsing dozens of data points into a readable report.
- Format normalisation — making different sources line up.
What AI doesn’t do well:
- UX judgment in context — “why isn’t this CTA working” needs business context the model doesn’t have.
- Brand quality — “this typography is wrong” is human judgment.
- Market positioning — “what should you do differently from your competitor” is strategy.
This is why I read the first twenty reports myself. I edit the AI output, drop in human-written notes on the “attention” sections, and tighten the language. After the first twenty, the patterns repeat and I move to spot-checks.
The PDF structure
- Summary — three highest-impact findings, one sentence each.
- Triage (Phase 1) — what to fix in a week.
- Foundation (Phase 2) — four to six weeks of structural work.
- Strategic (Phase 3) — longer-horizon rebuilds.
- What this audit doesn’t cover — explicit, listed.
That last section earns the report. “What this audit doesn’t cover” does two jobs: it sets legal boundaries, and it sets up the conversation about a paid engagement.
Risks I run
Risk 1: AI hallucination. Mitigation: every finding cites a source (line / header / file). No source, no entry in the PDF.
Risk 2: Cloudflare blocks the stealth fetch. Mitigation: residential IP pool plus reasonable rate limits. If a site is fully blocked, the report says so explicitly — partial reports are labelled as partial.
Risk 3: This reads like cold outreach. Mitigation: opt-in only. I never email someone who didn’t fill the form. The partner submits their own URL; the report goes to their own inbox.
Why I’m publishing this
Most studios that sell “AI audits” hide how the pipeline works. We do the opposite: the process is in the open so partners can judge how reliable the report is for themselves.
This isn’t “we use AI.” It’s how we use AI.