All 115 Ecommerce Checkout UX Rules We Audit Against
Ecommerce checkout UX rules are the specific, testable conditions a store's product page, cart and checkout must meet to avoid losing a sale, things like showing shipping cost before payment, validating an address before order confirmation, or marking up price so a crawler reads it correctly. UXFix checks stores against 115 of these rules, split across eight sections, scored separately for human shoppers and AI shopping agents.
What a checkout UX rules engine actually checks
A rules engine is not a vibe check. It is a fixed list of pass/fail conditions applied the same way to every store, so results are comparable across audits and over time.
UXFix's engine runs each of the 115 rules against a live store, twice: once simulating a human shopper's path through product page, cart and checkout, and once simulating an AI shopping agent reading the same pages. The two scores often diverge sharply. A store can pass 90% of human-facing rules and still fail half the agent-facing ones, usually because price and availability live in JavaScript-rendered elements an agent never sees.
This is the same reasoning Baymard Institute uses in its own checkout usability research, where a fixed set of usability guidelines is tested against hundreds of live sites rather than judged case by case. We built our checklist to be exhaustive rather than opinionated: every rule below is something we can observe and score, not a matter of taste.
The 115 rules, organized by section
The checklist splits into eight sections. Product page and checkout flow carry the most rules because that is where most abandonment happens, per Baymard's long-running cart abandonment research.
| Section | Rules | Where it matters most |
|---|---|---|
| Product page | 22 | Price clarity, stock status, structured data |
| Cart | 18 | Cost transparency, editability |
| Shipping & delivery | 12 | Timing disclosure, address accuracy |
| Checkout flow & forms | 20 | Friction, validation, guest checkout |
| Payment | 15 | Method choice, error handling |
| Trust & security | 10 | Badges, policy visibility, contact info |
| Mobile | 10 | Tap targets, keyboard type, page weight |
| AI agent readiness | 8 | Schema, crawlability, machine-readable status |
Product page (22 rules)
- Price shown in the currency the visitor expects, not just the store default.
- Sale price and original price both visible when a discount applies.
- Stock status stated in words, not just a colour dot.
- Delivery estimate shown before add to cart, not after.
- At least one image shows the product in use, with scale or context.
- Size or fit guidance linked from the page, not buried in a separate FAQ.
- Variant selection does not reset scroll position or page state.
- Reviews visible near the fold, not hidden behind a separate tab only.
- Star rating shown next to the price, not just at the page bottom.
- Return policy summary visible on the page itself.
- Shipping cost or free-shipping threshold mentioned on the product page.
- Product title matches the terms shoppers actually search.
- Product schema markup present so price and availability are machine-readable.
- Add to cart button is the visually dominant action.
- Quantity selector does not default above 1.
- Out-of-stock items show a restock date or notify-me option.
- Cross-sell content does not push the primary product below the fold.
- Page load time under roughly 2.5 seconds on mobile, per Core Web Vitals targets.
- Breadcrumb navigation present for users and crawlers.
- Product videos have captions or a text alternative.
- Trust signals sit near the buy button, not only in the footer.
- Delivery date shown consistently with what checkout later confirms.
That last point connects directly to a pattern we see constantly: stores that quote one delivery estimate on the product page and a different one at checkout. Our audit notes cover this in more depth in why shoppers abandon checkout when delivery dates aren't shown.
Cart (18 rules)
- Cart total updates instantly on quantity change, no manual refresh.
- Shipping cost shown in cart, not deferred to checkout step one.
- Discount code box is not left empty and prominent if no code applies.
- Save-for-later available instead of forcing deletion.
- Estimated delivery window shown per line item.
- Quantity editable without leaving the cart page.
- Cart persists across sessions for logged-in and, where possible, guest users.
- Upsell offers do not obscure the checkout button.
- Tax shown or clearly labeled "calculated at checkout," with a reason given.
- Line items show variant details, not just the product name.
- Remove-item action has an undo or confirmation step.
- Header cart icon updates in real time across the site.
- Free-shipping threshold shown with a progress indicator, not just static text.
- Currency conversion shown live if the store sells across borders.
- Empty cart state suggests a next action instead of a dead end.
- Gift wrap or note options do not require leaving the cart flow.
- Cart summary sticky on scroll for long mobile carts.
- No more than one prominent CTA competing with "proceed to checkout."
The discount code box deserves its own callout. A box that invites a code but has none to offer sends shoppers hunting across the web for one, and many never come back. We go deeper on this in why a discount code box quietly kills your cart conversion rate.
Shipping & delivery (12 rules)
- Delivery date estimate shown before checkout begins, not after payment.
- Multiple shipping speeds offered with clear price differences.
- Cutoff time for same-day or next-day delivery stated plainly.
- International shipping cost and customs disclaimer shown before checkout, if relevant.
- Fulfillment origin disclosed so delivery estimates are credible.
- Shipping cost never introduced for the first time at payment.
- Split shipments explained in advance if items ship separately.
- Address validation catches errors before confirmation, not after.
- PO Box or rural delivery limitations disclosed, not discovered on failure.
- Click-and-collect shown with real-time store stock, if offered.
- Delivery guarantee or SLA stated for premium shipping tiers.
- Return shipping cost and process stated before purchase.
Shipping cost surprise is the single most common failure we log across all 115 rules. If you fix nothing else this quarter, fix this one. There's a full breakdown in why shoppers abandon their cart over shipping costs.
Checkout flow & forms (20 rules)
- Guest checkout available and offered before forcing account creation.
- Progress shown as steps so shoppers know how much is left.
- Country auto-detected to set the correct address format.
- Inline field validation, not only errors after full submission.
- Address autocomplete available to cut typing errors.
- Only necessary fields requested, no extraneous data collection.
- Back button preserves entered data instead of resetting the form.
- Error messages are specific ("card number invalid"), not generic ("an error occurred").
- Order summary stays visible through every checkout step.
- Editing the cart from checkout does not restart the whole flow.
- Phone number field states why it's needed.
- Autofill-compatible fields for name, address and card, per browser standards.
- Minimal-step checkout preferred over unnecessary multi-page flows.
- Newsletter opt-in unchecked by default.
- Terms checkbox does not block submission with unclear required fields.
- Session timeout warning given before cart or form data is lost.
- Checkout navigable by keyboard alone, consistent with WCAG guidance.
- Confirmation page includes an order number and clear next steps.
- Email confirmation sent within minutes, with full order details.
- Checkout URL uses HTTPS with no mixed-content warnings.
Account creation forced at the wrong moment is its own abandonment category, distinct from form friction generally. We cover it separately in why shoppers abandon checkout at account creation.
Payment (15 rules)
- Multiple payment methods offered: card, wallet, buy-now-pay-later where relevant.
- Accepted card logos shown before the payment step, not just on arrival.
- Payment errors state the actual reason, not just "try again."
- Saved payment method offered to returning logged-in users.
- Currency at payment matches the currency shown throughout browsing.
- No surprise fee added at card entry.
- Payment step does not require re-entering already-supplied address data.
- Security indicator shown near the payment form.
- Total price at payment matches the cart total exactly.
- Retry after a failed payment does not needlessly clear entered card details.
- Split payment or gift card redemption explained clearly, if offered.
- Verification steps (3D Secure etc.) briefly explained to avoid confused drop-off.
- Apple Pay or Google Pay offered where technically supported.
- Refund timeframe stated near payment confirmation.
- VAT or invoice fields, where relevant, do not block checkout completion.
- State the exact reason a payment failed (declined, expired, wrong CVV).
- Keep the entered card number in place after a failed attempt so shoppers don't retype everything.
- Show a generic "something went wrong" message at the one step where trust matters most.
- Introduce a processing fee only after the shopper has entered card details.
Payment is the step with the highest cost of failure per attempt, because a shopper who reaches it has already cleared every other hurdle. More detail on this in why do shoppers abandon checkout at payment.
Trust & security (10 rules)
- Trust badges placed near the CTA, not only in the footer.
- Physical address and contact details available, not just a contact form.
- Reviews or ratings shown independent of the store's own site.
- Privacy policy linked from within the checkout flow itself.
- Valid HTTPS certificate on every checkout page.
- Return and refund policy linked directly from cart and checkout.
- Customer service reachable during checkout, not only pre-purchase.
- No countdown timers without a real, verifiable deadline.
- Data collected at checkout matches what the privacy policy discloses.
- Business registration or company number shown where regulatory trust applies.
Trust signal placement is a small design decision with an outsized effect. We've measured this specifically in why shoppers abandon checkout without trust badges or security signals.
Mobile (10 rules)
- Tap targets meet minimum size guidance, no misclicks on tiny buttons.
- Checkout fields trigger the correct mobile keyboard (numeric for card, email for email).
- Sticky add-to-cart and checkout buttons on long mobile pages.
- No horizontal scrolling required at any step.
- Font size legible without pinch-zoom.
- Mobile page weight optimized to hit Core Web Vitals thresholds.
- Autofill and password managers work without breaking layout.
- Modal pop-ups do not block their own close button on mobile.
- One-handed thumb reach considered for primary CTAs.
- Mobile wallets prioritized over manual card entry.
Mobile-specific breakage accounts for a disproportionate share of the abandonment we log, covered fully in why shoppers abandon checkout on mobile.
AI agent readiness (8 rules)
- Price and availability marked up with schema.org structured data.
- Product details accessible without required JavaScript rendering.
- Checkout does not rely on CAPTCHA that blocks legitimate automated agents.
- Displayed price matches structured data exactly, with no drift.
- Robots.txt and meta tags do not block legitimate crawling of product pages.
- Shipping and return terms exist as crawlable text, not only inside images.
- Checkout steps use standard HTML forms, not unlabelled custom components.
- Order confirmation returns a machine-readable status for agent-initiated purchases.
What changes when the shopper is an AI agent?
Agents don't get confused by a busy layout. They get blocked by missing structured data, JavaScript-only pricing, and forms with no accessible labels. A page a human finds cluttered but usable can be completely unreadable to an agent, and a page that scores well on human usability can still fail every one of the eight agent-readiness rules.
Schema.org's product markup guidance is the baseline most agents rely on to read price, availability and identifiers correctly. If your price only renders after a JavaScript call, an agent may quote the wrong number entirely, a failure mode we detail in why AI shopping agents misread your prices. Combine that with a CAPTCHA at checkout or a login wall before pricing is visible, and the agent abandons the session outright, which we cover in why AI shopping agents abandon checkout on your store.
This is also why ChatGPT, Gemini and similar tools sometimes skip a perfectly good store when recommending where to buy something, a pattern explored in why ChatGPT and Gemini don't recommend your store. Crawlability failures upstream of checkout, covered in why AI shopping agents can't find your product pages, often explain the gap before agent checkout rules even come into play.
Where most stores lose the most points
Across the audits we run, three sections account for the majority of failed rules: shipping cost disclosure in cart and product page, form friction in checkout, and generic payment error messaging. None of these require a redesign. Most fixes are copy changes or moving an existing element earlier in the flow.
Shipping cost first appears on checkout step two, after the shopper has entered an address.
Shipping cost, or a clear "from $X" estimate, appears in the cart before checkout begins.
The pattern holds for delivery timing too. Baymard's checkout usability research and our own audit data agree on the same point: the fewer surprises between cart and payment confirmation, the higher the completion rate, full stop.
How to work through this checklist this week
Don't try to fix all 115 rules in one sprint. Work section by section, starting with the ones tied to money: shipping and payment. A realistic order:
- Pull your current product page, cart and checkout against the shipping and delivery rules above. Fix any point where cost or timing is disclosed later than it needs to be.
- Check payment error messages manually by triggering a decline in a test environment. Rewrite anything generic.
- Run your checkout through keyboard-only navigation once, per WCAG's accessibility guidance, and note where it breaks.
- Check whether your product price renders in the raw HTML or only after JavaScript executes, since that single detail decides whether AI agents read it correctly.
- Revisit the trust and mobile sections last, since they tend to have the smallest individual impact but compound with everything else.
A fixed rule set matters because it turns "our checkout feels fine" into something falsifiable. You either show the shipping cost before checkout or you don't. You either have Product schema markup or you don't. That specificity is the whole point of running an audit instead of a gut check.
Frequently asked questions
Why 115 rules specifically, and not a shorter list?
We arrived at 115 by testing against real failure patterns across hundreds of audits rather than picking a round number. Some sections, like AI agent readiness, are intentionally short because there are fewer distinct failure modes; others, like checkout flow and forms, are long because friction shows up in many small, independent ways. The number is a byproduct of what we actually observe breaking, not a target.
Do I need to pass all 115 rules to have a good checkout?
No. Most healthy stores pass roughly 80 to 90 percent of the human-facing rules and still convert well, because a handful of rules (shipping cost timing, guest checkout, payment error clarity) carry far more weight than the rest. The full list is a diagnostic tool, not a pass/fail exam. Use it to find your biggest gaps, not to chase a perfect score.
How is the human score different from the AI agent score?
The human score simulates a shopper reading rendered pages the way a browser displays them. The AI agent score simulates how an automated agent parses the same pages, which relies far more heavily on structured data, HTML semantics and crawlability than on visual layout. A store can score 95 for humans and 60 for agents if pricing or availability depends on JavaScript the agent never executes.
Can I use this checklist without running a formal audit?
Yes. Every rule above is something you can check manually with a browser, a mobile device, and roughly an hour of your time. A formal audit mainly saves time by running all 115 checks automatically and comparing your store against benchmark data, but the checklist itself is meant to be usable on its own.