SEO tags, sitemap and legal pages
SEO + metadata + legal generator
For when the answer to “People should find it on Google, and it needs privacy/terms pages” is yes.
Generates canonical/OG/Twitter tags, JSON-LD, sitemap.xml, robots.txt, and privacy/terms pages from the config the site already has — plus a --check that fails the build when launch placeholders remain.
Built by hand again in 9 of 20 audited projects before this existed. Each rebuild was another chance to make the mistake below.
Skip the rebuild
You do not write this one. It arrives in your project as ordinary source you can read, change and keep, with its audit record and its caveats beside it.
- Download the Playground. It is free and runs on your own machine.
- Start a new app and tick “People should find it on Google, and it needs privacy/terms pages”.
- This block is written in, along with anything else you ticked.
The mistake it removes
The single most repetitive hand-written work in the audit (9/20 sites). DD keeps failing sites on the same two mechanical things: placeholders shipping in canonical URLs, and no privacy/terms on a site that takes money.
What is already handled
Each of these was checked by running the code, not by reading it.
- JSON-LD is escaped for script context: a business_name containing '</script><script>alert(1)</script>' round-trips as DATA — verified with the real payload, asserting the block still parses as JSON and still contains exactly one script element.
What the audit found
Named rather than summarized. The reasoning behind each one ships inside the block, so it travels with the code instead of living on a page you have to trust.
- Generated privacy/terms are a baseline, not legal advice minor · Legal & compliance pages
- check_placeholders scans text files only minor · Correctness
What you still have to do
A copied file cannot own your secrets, your host or your legal obligations. This is the part the block deliberately does not claim.
- Serve the generated sitemap.xml and robots.txt at your domain root, and set base_url to the real origin. The generator writes correct files; whether a crawler can fetch them at the expected path is a hosting decision it cannot make.
- Wire `--check` into your build or CI so it can fail a deploy. Unrun, it fails nothing, and shipping launch placeholders in canonical URLs is the exact failure it exists to stop.
- Have the generated privacy and terms reviewed for your business and jurisdiction, and keep them in step with what the site actually collects. They are a baseline written from your config, not legal advice.
- aggregateRating is emitted only when both rating and review_count exist; inventing review counts violates Google's policy.
What lands in your project
python
- python/seo_kit.py
Import SeoKit, or run as CLI: python3 seo_kit.py --config config.json --out output/ --check. Stdlib only. --pages takes [{path, title, description, image, lastmod}]: path is required, lastmod goes in the sitemap, and title+description (BOTH, or neither) write a meta/<slug>.html head block for you to include in that page. An unknown page key is an ERROR — this generator does not accept a value and then drop it. Choosing each path: Every page URL carries the page's target keyword: lowercase, hyphens, the city for a local page, no dates or ids (`/cape-coral-realtor/`, not `/page2/`, `/2026/09/new-post/` or `/services?id=4`).
What you supply
- business_name — required — refuses to generate without it
- base_url — required, absolute — a relative og:image silently shows no preview
- address/email/phone/rating/review_count — optional — JSON-LD only includes what's real
Licensed MIT. It is a starting point, not a finished product.
Get it
Download the Playground See the other blocks
Nothing here is locked. The files are yours, in your folder, under a permissive license.
Questions
- Is SEO tags, sitemap and legal pages audited?
- Yes. A full due-diligence audit was run on 2026-07-17 and the verdict was a pass.
- What do I still have to do myself?
- Serve the generated sitemap.xml and robots.txt at your domain root, and set base_url to the real origin. The generator writes correct files; whether a crawler can fetch them at the expected path is a hosting decision it cannot make.
- How do I get this code?
- Download the Playground, start a new app, and tick “People should find it on Google, and it needs privacy/terms pages”. The block is written into your project as ordinary source you can read and edit.
All pre-built code blocks · Learn to build from zero · The coding guide