Pavle
CRO

Ecommerce CRO Audit: 7 Steps for Shopify, Woo and Magento

Pavle Lucic
Pavle LucicJuly 15, 2026 · 8 min read
Key takeaways
  • Audit what you can actually change: standard Shopify's checkout is hosted and locked, while WooCommerce and Magento give you full control.

  • Pick a non-promotional analytics window first. Auditing on Black Friday data gives you a funnel that does not exist the rest of the year.

  • Category, on-site search and filter pages are the highest value surfaces almost every ecommerce CRO audit skips.

  • Move account creation to the order confirmation page and the guest checkout argument disappears.

  • Below roughly a thousand sessions and a hundred conversions per variant per month, ship the fix instead of testing it.

On this page

What an ecommerce CRO audit is, in one paragraph

An ecommerce CRO audit is a structured review of every step a shopper takes, from the category page to the order confirmation screen. You run it against a real, non promotional slice of your analytics. The output is a ranked list of fixes, split into two piles: ship now, or test first.

Two things make it different from a generic CRO audit. Your platform decides what you are even allowed to change. And ecommerce funnels have surfaces a software signup flow never has: category grids, onsite search, filters, and a confirmation page after the sale is already closed.

Every check here runs mobile first, desktop second. That is the default lens throughout, so we will not repeat it in every section.

Want the reasoning behind every check, not just the ecommerce specific ones? Read the full CRO audit process first, then apply it to your store.

Step 1. Find out what your platform actually lets you test

Start here, because it decides everything downstream. On a standard Shopify plan, the checkout is hosted by Shopify itself. You get settings, not surgery: you can turn things on or off, but you cannot restructure the page or split test it. Real checkout customisation and A/B testing need Shopify Plus with Checkout Extensibility. WooCommerce and Magento are self hosted, so cart and checkout are fully yours.

| Platform | Cart editable | Checkout editable | Checkout A/B testable | Where your audit effort should go | |---|---|---|---|---| | Shopify (standard plans) | Yes | Settings only | No | Product, cart, category, confirmation | | Shopify Plus | Yes | Yes (Checkout Extensibility) | Yes | Full funnel, checkout included | | WooCommerce | Yes | Yes | Yes | Full funnel | | Magento / Adobe Commerce | Yes | Yes | Yes | Full funnel | | BigCommerce | Yes | Partial, plan dependent | Limited | Product, cart, category, plus checkout where available |

That is the whole point of this step. If your checkout is locked, do not fill your report with checkout recommendations nobody can build. Move the weight of the audit upstream, onto the product page, cart drawer, and category pages, and downstream onto the order confirmation page, which is more editable than most people assume.

One warning. Apps that promise to customise checkout usually inject scripts into the theme, not the hosted checkout itself, so test what they actually touch.

Step 2. Pick a representative analytics window before you look at anything

Pick your reporting window before you open a single page. This decision distorts the audit itself, not just the tests you run afterward.

Audit a promo week like Black Friday and you get a funnel that does not exist the other fifty weeks of the year. Rule of thumb: use 4 to 8 weeks of non promotional traffic, excluding peak season, sales, and paid spikes. Then segment by device, by traffic source, and by new versus returning, since branded search and paid carry different intent before design enters the picture.

One check comes before all of this: confirm your analytics track what you think they track. A quick tracking integrity check saves you from auditing fictional numbers.

Step 3. Audit category, onsite search and filter pages

Most guides skip this on the way from homepage to product page to checkout, and it is where real revenue quietly leaks out.

Start with onsite search. Look at how often it returns nothing, and read the actual queries behind that number. It is the highest signal, lowest effort finding in the whole audit. If people search a product name you sell under a different word, you now know exactly what to fix. Check synonym handling, misspelling tolerance, and whether search is visible on mobile without an extra tap.

Then category pages:

  • What is the default sort? "Featured" often just means whatever the merchandiser picked that week.
  • Does the filter set match how people shop this category, not how your catalogue happens to be organised?
  • How many filters sit buried inside a mobile drawer before someone gives up?
  • Are price, variant availability, and review count visible in the grid, or hidden behind a click?
  • Does pagination or infinite scroll break "back to results" on mobile?

Once analytics run out, this becomes heuristic evaluation, expert judgment instead of a number. That is normal, and it still counts.

Step 4. Product pages: past 'add more photos'

Product pages get audited constantly, usually for the wrong things. Photos rarely explain a lost cart.

Start with cost. Is the full delivered price, shipping, tax, duties where relevant, visible before someone reaches the cart? The Baymard Institute's long running checkout research consistently names unexpected costs at the final step as one of the top reasons people abandon a purchase. Show that cost earlier and a whole category of late stage drop off goes away.

Next, variant selection. Are out of stock variants still selectable, so people tap them and get nothing? Does picking a variant silently reset the photo gallery? Does the URL update, so a customer can share the exact variant they are viewing?

Delivery expectations beat shipping labels. "Arrives Thursday" tells someone more than "standard shipping" ever will.

Reviews need presence, recency, and honesty. Hiding every negative review does not protect trust. It costs trust.

Step 5. Cart and checkout, scoped to what you can change

Call back to step one. If your checkout is locked, these findings are settings and app decisions, not experiments. Write them down anyway, just tag each one "config" instead of "test".

In the cart: are the costs shown here final? Is the discount code field a giant invitation to leave and go hunting for a coupon? Can someone edit quantity or variant right in the drawer, without a page reload?

In checkout: is guest checkout available at all? Step six has a better fix than the usual debate. Count your fields against what you actually need to ship an order. Check address autocomplete, and whether one error wipes out everything already typed. Confirm payment methods match your market, wallets especially, since most of this traffic sits on a phone.

Most checkout findings on standard Shopify resolve to "turn this setting on" or "remove this app". That is a legitimate outcome.

Step 6. Audit the order confirmation page (the surface everyone skips)

Most guides stop at "optimise your checkout" and never mention what happens after someone pays. The confirmation page is doing real work, or leaving it undone.

Tip

Move account creation after purchase instead of forcing it before checkout. Offer to create the account right on the confirmation page, pre filled from the order just placed. The customer already typed their name, email, and address once. This dissolves the forced accounts versus guest checkout argument instead of picking a side.

Review requests do not belong on this page either. The customer has not received the product yet, so asking now just teaches people to ignore the ask. Set the expectation here, and send the real request later.

Post purchase offers convert well because there is no payment friction left. A one click add to an existing order is one of the few post checkout surfaces that is extensible even on standard Shopify.

Order tracking matters too. Every "where is my order" email your support team answers started as a design failure on this exact page.

Step 7. Decide what to ship and what to test

The agencies selling this work tend to gate their services at tens of thousands of sessions a month, or four figure monthly retainers. Most stores asking the question are nowhere near that.

One rule on testing volume: below roughly a thousand sessions and a hundred conversions per variant per month, a test will not reach significance in a useful timeframe. For the full reasoning, read the traffic floor and why most CRO programmes fail.

| Finding type | Ship it | Test it | |---|---|---| | Clear usability defect or broken thing | Always. Testing a bug is theatre. | Never | | Common, well documented issue (hidden shipping cost, no guest checkout) | Yes, if you are under the floor | Only once well above it | | Ambiguous trade off (price framing, layout, copy tone) | Pick one and monitor, if under the floor | Yes, if over the floor | | Anything touching a locked checkout | Change the config, monitor before and after | Do not call it a test |

Under the floor, most of this is simple. Ship the clear fixes, pick one version of the ambiguous ones, and monitor.

Bring in outside eyes once your ship pile is empty and every finding left is a genuine trade off. That is when a proper CRO audit earns its cost.

Frequently asked questions

Can you A/B test the Shopify checkout?

Not on standard Shopify plans. The checkout is hosted and locked, so you can change settings but not run split tests on it. Checkout customisation and testing require Shopify Plus with Checkout Extensibility. Everything before the checkout, including product pages and the cart drawer, is testable on any plan.

Is a CRO audit different for Shopify, WooCommerce and Magento?

The findings are similar, but what you can act on is not. WooCommerce and Magento are self hosted, so cart and checkout are fully editable and testable. On standard Shopify the checkout is locked, so the audit weight shifts to category, search, product and post purchase pages.

Should small ecommerce stores run A/B tests or just fix issues directly?

Fix directly. Below roughly a thousand sessions and a hundred conversions per variant per month, an A/B test will not reach significance in a useful timeframe. Ship the clear usability fixes, and save testing for genuinely ambiguous trade offs once traffic supports it.

What is a good ecommerce conversion rate?

There is no universal good number. Conversion rate varies enormously by category, price point, device and traffic source, and a branded or returning visitor traffic mix moves it more than design does. Compare against your own non promotional baseline rather than a published benchmark.

How often should you audit your store?

A full audit once or twice a year is enough for most stores, plus a short focused review after any major change such as a theme update, platform migration, new checkout app or a tracking rebuild. Avoid auditing on peak season data, because promotional traffic distorts the baseline.