Guides

HTTPS and a working checkout: Google’s third website audit item

By Terry Ecom · Last reviewed 2026-08-31 · Source: Google Merchant Center Help

Identity and policies get the attention. The third item on Google’s list is mechanical — do the pages load, over HTTPS, and does the buy path work — and it is the one a theme or app update quietly breaks.

What Google published

For Misrepresentation and “Website needs improvement”, the audit instruction is to fix broken links and verify that checkout is fully functional and secured with HTTPS. The fully-functional-store article adds that links must not 404 or bounce to the homepage instead of the intended destination.

Landing-page requirements sit alongside this: a URL you submitted has to show that product and offer a way to buy it.

Why “Shopify handles HTTPS” is not the whole answer

Shopify serves storefronts and checkout over HTTPS by default, so the certificate is rarely the issue. What still breaks is everything around it: an http:// link hardcoded in a theme or a policy page, an app embedding a resource over http, a custom domain mid-migration, or a redirect chain that drops the secure scheme on the way through.

The other half of the item is functionality. A checkout that loads but cannot be reached — a hidden cart, a password-protected storefront, a required app that fails for a first-time visitor — fails “fully functional” even though the padlock is present.

What GMC Scout checks, and what it does not

Scout checks HTTPS enforcement, runs an HTTP status check on every seeded and discovered URL for full 404 coverage, and flags outbound links pointing at a different domain than the store — a frequent sign of a half-migrated theme or a copied template.

It does not complete a test purchase, enter payment details, or verify that a card is charged correctly. Do that pass yourself in a fresh incognito window before you request review: open a product, add to cart, and go as far as the payment step.

FAQ

Does Shopify give me HTTPS automatically?

Yes for the storefront and checkout on a properly connected domain. What Scout still finds are http:// links inside theme and policy content, and outbound links to the wrong domain.

Does GMC Scout test my checkout end to end?

No. We confirm HTTPS and crawl publicly reachable pages. Completing a purchase is a manual check and we will not claim otherwise.

My store is password-protected while I finish building. Is that a problem?

For a review, yes. A storefront a visitor cannot enter cannot pass a functionality check. Remove the password before you submit or appeal.

Sources

Related guides

Scan the Shopify storefront before you spend a review.

Free scan with signup. 70+ checks. Issue counts and categories on the free report.

Start free scan