A DTC founder installs a new post-purchase upsell app on a Wednesday. By Friday, their Google Ads account is reporting conversions up 40% week over week with no change in spend or creative. Nobody touched a campaign. What happened is the new app's own conversion pixel started firing alongside the GTM container that was already tracking the same checkout_completed event, and for two days the business was making decisions off a number that was never real.
That is the failure mode a standard Shopify audit checklist cannot catch, because it was not built to look for it. Search "shopify audit checklist" and the top ten results all run the same playbook: Core Web Vitals, robots.txt, duplicate meta descriptions, app count, tap target sizes. Useful work, and worth doing. But a store can clear every item on that list and still be reporting revenue that is off by double digits, because none of those checks touch measurement.
Why the standard checklist misses this
The public Shopify audit checklists are written for a different audience: SEO consultants and CRO agencies optimizing for rankings and page experience. That is a legitimate, separate discipline. It is also why "shopify audit checklist" results cluster around site speed, structured data, and UX rather than whether the purchase count in your GA4 property or ad accounts matches what Shopify's own order export says happened.
A 289,000-store benchmark study from StoreInspect found the average Shopify store runs 4.2 detectable tracking pixels, climbing to nearly 9 on stores with over 200,000 monthly visitors, and that count only includes what loads client-side. Every one of those pixels is a potential second source writing to the same event. A speed-and-SEO checklist has no reason to open that question. A measurement-first audit has no other job.
The checklist a measurement-first Shopify audit actually runs
1. Count your tag sources per conversion event, not per app
List every place a purchase, add-to-cart, or checkout event could originate: the theme's GTM container, any sales-channel app's native pixel, a checkout extensibility Web Pixel, and any server-side integration (Shopify Flow, a middleware tool, a CAPI gateway). If two sources can both fire the same event for the same order, you have a double-counting risk whether or not either one is "broken."
2. Reconcile reported revenue against the order export
Pull Shopify's order export for a fixed date range and compare total order revenue against what GA4, Meta, and Google Ads each reported as purchase revenue for the identical window. Any platform more than a few percent off needs an explanation, not a shrug. This single check is the difference between an audit and a config review, and it is the step every free tool skips, as detailed in a GA4 Shopify revenue mismatch reconciliation.
3. Check what currency and multi-currency apps actually send
If the store runs Shopify Markets or a third-party currency converter, confirm the value and currency parameters your tags send match what the customer was actually charged, not the store's base currency. A mismatch here inflates or deflates every reported revenue number by the conversion spread, invisibly.
4. Verify checkout-step events survived the last platform update
Confirm begin_checkout, add_shipping_info, add_payment_info, and purchase still fire correctly after checkout extensibility. Since checkout.liquid stopped rendering the Information, Shipping, and Payment steps, any tag that depended on a theme script or page-level GTM container on those steps is dead weight that looks installed and fires nothing. The supported path is Shopify's Web Pixels API, which runs in a sandbox and subscribes to standard customer events instead.
5. Audit app-level pixel conflicts, not just app count
Go through every installed app with marketing or analytics permissions and ask what it tracks, not just whether it is used. The GTM container audit most agencies run already catches duplicate tags and orphaned triggers inside the container itself; this step extends that same question to apps operating entirely outside GTM's visibility.
6. Confirm key events are labeled correctly, not just present
In a delivered tracking audit, we found 10 of 13 GA4 event triggers orphaned inside a GTM container that otherwise had a complete 42-variable measurement plan built for it, and no GA4 event tag had ever been created for the real purchase event. The container looked thorough. The key event it needed most had never fired once.
7. Check what the consent banner app is actually blocking
A consent management app installed through the Shopify App Store sits in front of every other tag on the list above. If it is scoped incorrectly, it can block tags for visitors it should not, or let tags fire for visitors who never consented, and neither failure shows up as an error anywhere in the admin. We have seen a consent banner configured to recognize only EU browser timezones leave every non-EU visitor permanently consent-denied, silently blocking ad and analytics tags store-wide for months. Test the banner's accept and reject paths from more than one region before trusting that it only touches the traffic it is supposed to.
8. Re-check after seasonal app installs, not just once a year
Shopify stores churn apps harder than most platforms around peak season: a countdown-timer app for Black Friday, a one-off upsell app for a product launch, a temporary currency widget for a regional push. Each one gets installed with marketing permissions, used for six weeks, and then "disabled" rather than fully uninstalled, often leaving a pixel script still registered. A tracking audit done in January on a store that added four apps for Q4 is auditing a different store than the one that ran the campaigns. Re-run the tag-source inventory in #1 any time an app with tracking permissions goes in or out, not on a fixed calendar.
Self-audit or pay for one: how to decide
Run the free site-health checklist and the tag-source inventory in #1 yourself first; both take under an hour and will surface the obvious problems without spending anything. If the reconciliation step in #2 turns up a revenue gap you cannot explain, if the store has added or removed more than two or three apps with tracking permissions in the past year, or if nobody on the team can say with confidence which app owns the purchase event, that is the point to stop self-diagnosing and bring in a fixed-scope Shopify tracking audit. A sample of what that audit actually documents, line by line, is in the tracking audit sample report.
For a broader look across tracking, CRO, paid media, and reporting together rather than tracking alone, the full ecommerce audit service scopes all four areas in one fixed-price engagement and credits the fee toward implementation if you move forward within 60 days. Either way, the test is the same one a site-speed checklist was never built to answer: does the number in your dashboard match what the store actually made.

