The method

The audit flags it. I check it.

The 2026 Booking-Path Audit is how Winter Growth Systems audits a med spa’s booking path: by walking it automatically — the same steps a patient takes, from landing on the site to the point where an appointment would be confirmed. The walk only reads what any visitor can see. Nothing is booked, and a person reviews every finding before a number is published.

This page exists so the articles do not have to keep re-explaining it. Every figure published anywhere on this site was produced the way this page describes, and where the method has a limit, the limit is written down here rather than left for you to discover in the footnotes.

Domains audited
221
Booking surface reached
140
Domains with findings
36
Snapshot taken
27 August 2026

The 2026 Booking-Path Audit: Winter Growth Systems audited 221 med spa booking paths across the Carolinas. The walk reached a booking surface on 140 of them; of those 140, 36 — 25.7%, about 1 in 4 — had at least one reviewed finding. Measured 27 August 2026, reviewed 7 September 2026.

The findings count is the reviewed one: the walk flagged 40 domains and four of those were rejected on review, which is the whole argument of this page happening to its own numbers. The 140 excludes the 19 domains whose booking vendor blocks crawlers and the 62 where no booking surface was found at all — nothing was walked there, so nothing is claimed about them.

The walk

It takes the steps a patient would take.

The audit is an automated walk of a practice’s public booking path: the pages a visitor lands on, the menus and buttons that promise an appointment, the tap-to-call links, the forms, and any embedded calendar the path hands off to. It runs on a phone-sized viewport as well as a desktop one, because that is where most of this goes wrong.

It is a data-only exercise. The walk observes what is publicly visible and records what happened, and it deliberately stops short of every action that would touch the practice:

No accounts are created.
Where a path wants a patient portal login, the walk stops at the login and records that it stopped there.
No bookings are placed.
The walk goes as far as the last screen before an appointment would be committed, and no further. Nobody has to release a slot afterwards.
Forms are filled with fake data and never submitted.
Text fields get visibly fictional values — a reserved example address, a 555 number that cannot ring anyone — and the screen is photographed. The fill routine has no way to submit: it cannot click a button or press Enter, and clicks on submit controls are refused. Even if it could, POST navigations are aborted at the network layer.
Nothing behind a robots file is walked.
If a site asks not to be crawled, it is not crawled. It still gets counted, in its own lane, so the denominator stays honest.
Findings

A finding is something the walk watched happen.

Only observable defects are counted. If a reasonable person could look at the same screen and disagree about whether it is a problem, it is not a finding — a figure assembled out of opinions is not a figure. Five kinds of defect make the count:

  1. 01

    Broken links. A booking link that resolves to an error, a redirect loop, or a page that no longer exists.

  2. 02

    Widgets that fail to load. An embedded calendar or booking tool that never renders, renders empty, or renders and then cannot be used.

  3. 03

    Error states in the path. A step that returns an error to the visitor rather than moving them forward.

  4. 04

    Phone-verification walls. A path that stops to demand a code by text before it will show any availability, on a first visit, with no alternative offered.

  5. 05

    Mobile breakage. A control that works on a desktop viewport and cannot be reached, read or tapped on a phone-sized one.

The audit flagged it. The audit does not say your site is broken.

That phrasing is part of the method, not a preference about tone. A walk sees one path on one day from one place. It cannot see whether the phones are ringing, whether the widget was mid-deploy, or whether the practice already knows. So a report says what was flagged, where, and when it was observed — and the person who owns the site decides what that means. Every finding is written so you can go and check it yourself, which is the only version of this worth anything.

The lanes

Every domain lands in exactly one lane.

Nothing is dropped from the set once it is in it. A study that keeps the sites it could read and discards the ones it could not is a study whose denominator moves to suit its headline, so the lanes below are exhaustive and they add up to the total.

Findings40
The walk reached the booking path and recorded at least one screenshot-backed defect or wall. Seven domains also matched a second lane — a broken booking link both is a finding and stops the walk — and they are counted here.
Clean27
The walk reached selectable appointment times, or a form it could fill with no wall in the way, and flagged nothing. This is a real result and it gets reported as one.
Incomplete73
The walk stalled at the booking vendor’s first screen — neither appointment times nor a wall on screen. Nothing was proven about the site in either direction. This lane measures the walk, not the booking path.
Robots-blocked19
Every route to booking led to a booking vendor whose robots file forbids entry, so the flow could not be photographed. The practice did not make that choice; their vendor did. Counted here, never folded into another lane.
Unreachable62
The walk never reached a booking surface at all. Most often nothing on the homepage offered one.

These are the lanes as the walk flagged them. The review that follows moved four domains out of Findings, to 36 — it did not change the population.

Unreachable is mostly an absence claim by a detector.

Forty-seven of the sixty-two are that claim exactly: nothing on the homepage offered a way to book and no tap-to-call link was found. That is a statement about what the walk could see, not a verdict on the site — unusual affordances and white-label booking subdomains get missed, and five domains are marked as blocked from making an absence claim at all, because a widget frame never expanded or a page never rendered. The rest of the lane is smaller and more literal: four robots files disallowing every booking path, three SSL failures, two booking pages that rendered empty after the long settle, and one stopped by the audit’s own read-only guard.

Each domain was visited once, inside a single window of about forty-one hours. There is no retry across days. A domain having one bad minute is in this lane on the strength of that minute, and the honest way to read the lane is as the walk’s reach rather than the site’s condition.

Review

The walk proposes. A person decides.

An automated walk is good at noticing that something did not work and bad at knowing what it was looking at. So nothing it flags is a finding until somebody has opened the same path and agreed, and four rules stand between a flag and a published number:

  1. 01

    Every published finding is read by a person first. No figure reaches an article on the strength of the walk alone.

  2. 02

    Candidates that turn out to be something else are rejected. A gift-card checkout is not a booking flow, however much it looks like one to a walk. It comes out of the count rather than staying in as a number that happens to help.

  3. 03

    Articles report aggregates and never name a practice. No audited business is identified, in the writing or in the figures, and no figure is cut so fine that it identifies one by elimination.

  4. 04

    Screenshots are anonymised before they are published. Practice names and logos are covered with a solid block, never blurred, because a blur looks reversible. Visible URLs are replaced with reserved .example domains rather than blocked, so a reader can still see that a URL is what they are looking at. Anything showing a patient or a staff member is cropped out entirely. If an image cannot survive that and still make its point, it does not run.

Scope

What these numbers do not cover.

A figure is only useful to somebody who can tell whether it describes them, so the limits come before the numbers rather than after somebody has generalised them.

Geography

The audited practices are primarily in the Charlotte area. This is not a survey of the Carolinas, and it is not a national sample — it is the region the work happens in. The exact distribution is 188 of 221 in the Charlotte area, then13 in Greenville, 12 in Charleston, 4in Sumter and 3 in Columbia — 220 practices plus one operator-controlled test domain.

Segments

Different audit cohorts are never pooled without being labelled as such. Two sets drawn at different times, or drawn different ways, average into a figure that describes neither of them — and the average is always the number that gets quoted, because it is the one that looks like a fact. Where a figure covers more than one cohort, it says so.

Time

Every finding is an observation on the day it was made. Sites get fixed, and some of these will have been. A finding is evidence about a moment, not a standing claim about a business.

Two things this page deliberately does not cover: who runs the audit, and what happens after it flags something.

Want the same walk on yours? Free.

I’ll walk your website the way this page describes, and you’ll get the findings in writing with the steps to reproduce every one of them.

Check my website — free

Thirty minutes. I'll show you what I found on your site, and you keep the written report either way.