Every finding below was tested directly with fresh curl requests and HTML/header inspection today. The crawl foundation is genuinely solid: this is a self-hosted WordPress site with full server-side rendering, a single canonical host (apex, non-www), HTTPS enforced in single-hop redirects, and clean canonical tags on the vast majority of pages — a much better starting point than most small-business sites. The score is held back by one real, provable duplicate-content problem (6 city-page pairs, both self-canonicalized and both indexable), two indexable form-utility pages, site-wide soft-404 behavior, and an absence of security headers.

Critical Findings

TECH-01Six duplicate city-page pairs, both indexable, neither canonicalized to the otherCritical

Confirmed live today: The Woodlands, Sugar Land, Shenandoah, Missouri City, Mission Bend, and Pecan Grove each have two URLs (a base slug and a -2 suffix variant). Every pair has its own self-referencing canonical and an index, follow robots meta — Rank Math is not aware these are duplicates, so Google has to resolve the cannibalization unassisted.

PairTitle A vs. BCanonicalByte size A / B
the-woodlands-txIdentical titleSelf / Self (not cross-canonicalized)290,670 / 290,148
sugarland-txIdentical titleSelf / Self291,844 / 289,967
shenandoah-txIdentical titleSelf / Self291,837 / 290,144
missouri-city-txNear-identical (stray comma)Self / Self291,901 / 288,995
mission-bend-txIdentical titleSelf / Self291,805 / 288,830
pecan-grove-txIdentical titleSelf / Self291,780 / 288,805

Sampled two pairs in full: the Woodlands pair is 97.9% identical body text, differing only by one extra hero-banner block; the Sugar Land pair is 98.4% identical. Both pages in every pair are also submitted in page-sitemap.xml.

Fix: pick the canonical URL per city (recommend the non--2 slug — it carries the "Houston based" phrase and likely more indexing age/link equity), 301-redirect the -2 variant into it, and remove the redirected URL from the sitemap.

TECH-02Every invalid URL soft-404s to the homepageCritical

Verified today on a nonexistent path and on the non-Rank-Math default sitemap location:

$ curl -sIL https://greenindustrytrees.com/this-page-does-not-exist-xyz/ HTTP/1.1 301 Moved Permanently Location: https://greenindustrytrees.com HTTP/1.1 200 OK $ curl -sIL https://greenindustrytrees.com/sitemap.xml HTTP/1.1 301 Moved Permanently Location: https://greenindustrytrees.com HTTP/1.1 200 OK

Every invalid path 301-redirects to the homepage and returns 200 instead of a real 404. Google Search Console will log these as Soft 404 errors, it wastes crawl budget re-crawling redirect targets that are all the same homepage, and any stale citation-site URL or mistyped link silently funnels to the homepage instead of surfacing as a fixable broken link.

Fix: locate the overly broad catch-all redirect rule (likely in .htaccess or a redirect plugin) and configure WordPress to return a genuine 404 status for unmatched paths.

High Findings

TECH-03Two form-utility pages are indexable and submitted in the sitemapFIXED — verified live Oct 4, 2026

Both confirmed Sept 25 with an indexable robots meta and present in page-sitemap.xml:

URLRobots meta (Sept 25)In sitemap? (Sept 25)
/thankyou/follow, index, ...Yes
/sign-up-sms/follow, index, ...Yes

Neither should be indexed: the thank-you page can rank directly and let visitors skip the contact form entirely (breaking lead-attribution tracking), and the SMS opt-in page has no independent search value.

Status: fixed in Session 1 (2026-09-29) via Rank Math's per-page Advanced tab (the bulk "Set to noindex" action was tried first and silently failed — had to be done individually per page). Re-verified live Oct 4, 2026: both pages now return follow, noindex, and neither appears in page-sitemap.xml anymore (Rank Math drops noindexed URLs from the sitemap automatically).

TECH-04No security headers present at allFIXED — verified live Oct 4, 2026

Full response header dump on the homepage, Sept 25:

HTTP/1.1 200 OK Server: Apache Content-Length: 308482 Cache-Control: max-age=0, no-cache, no-store, must-revalidate Expires: Mon, 29 Oct 1923 20:30:00 GMT Pragma: no-cache Content-Type: text/html; charset=UTF-8

Missing: Strict-Transport-Security (HSTS), X-Content-Type-Options, X-Frame-Options/CSP frame-ancestors, and Referrer-Policy. None of these directly move rankings, but their absence is a standard clickjacking/MIME-sniffing exposure and an increasingly common trust signal.

Status (Oct 4, 2026): found the real root cause of the caching bug first — WP Fastest Cache's own plugin code unconditionally writes the no-store/Expires: 1923 block into .htaccess, hardcoded with no settings toggle, and hand-editing it directly would be overwritten on the next plugin regeneration. Fixed safely by adding a separate block after the plugin's section (Apache's Header set processes in order, last one wins): HSTS, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy are now live, and the cache-control header is fixed too (see Performance). .htaccess was backed up first and syntax-validated with apachectl configtest before and after.

Medium and Low Findings

TECH-05"local-sitemap.xml" contains no page URLs, only a KML fileMedium

Fetched directly today — the entire file:

<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"> <url> <loc>https://greenindustrytrees.com/locations.kml</loc> <lastmod>2024-04-06T03:36:52+00:00</lastmod> </url> </urlset>

This is Rank Math's Local SEO module output (a single-placemark KML export, not a real sitemap of pages). It is valid XML and not actually breaking anything — the city pages are fully covered by page-sitemap.xml instead — but the name is confusing scaffolding that shouldn't be mistaken for "the city pages have their own sitemap."

TECH-06No standalone LocalBusiness/Organization entity in the homepage JSON-LDMedium

Place/PostalAddress nodes are present but nested rather than exposed as a standalone entity in the way a local service business typically needs. Full schema inventory and generated fixes are on the Schema page.

TECH-07Case-sensitive URLs return 200 instead of redirectingLow

/Tree-Removal-Services/ (capitalized) returns 200 directly rather than 301-redirecting to the lowercase canonical. Rank Math does correctly emit the canonical tag pointing to the lowercase URL, which should prevent separate indexing, but relying on the tag alone leaves a duplicate-content vector open to tools that don't honor canonicals.

TECH-08Minor cleanup itemsLow

A footer credit link still points to http://www.wabuweb.com (not https://) — cosmetic, doesn't trigger mixed-content warnings. No IndexNow integration detected (Rank Math supports it natively but it isn't enabled) — a free, quick win for faster Bing/Yandex re-crawl once the duplicate-page cleanup ships.

What Passes

  • HTTPS enforced correctly; all www/http variants collapse to the apex host in a single redirect hop
  • Valid Let's Encrypt certificate, no mixed content on subresources
  • Fully server-side rendered — ~5,200 words of visible body text present in raw HTML with no JS execution required; no CSR/SPA risk
  • robots.txt is clean: only /wp-admin/ is blocked, sitemap directive present, no accidental site-wide disallow
  • All three sitemap files are valid, well-formed XML, well under the 50,000-URL limit (71 total entries)
  • Clean, human-readable URL slugs throughout with consistent trailing-slash convention
  • Duplicate city-page pairs, indexable utility pages, and soft-404 behavior: the three structural fails above