The situation
Kiboko Tours & Travel is a Kenyan safari operator selling private tour packages (enquiry, then quote, then deposit) and, soon, group safaris you can pay for online. They came to me with a simple question: why aren’t we getting enquiries like we used to?
Nobody had a clear answer, because nobody had looked at the whole path at once. So I pulled everything: 16 months of Search Console, a year of GA4, Clarity recordings, the site code, and their booking database.
What the data said
First, the headline. Kiboko hadn’t slowly lost interest from customers. It had slowly disappeared from Google.
Digging into why turned up a chain of problems, each one making the next worse:
- Google had indexed the wrong copies of the pages. Broken canonical tags and empty titles meant Google picked the non-www, trailing-slash versions. 0 of 44 package URLs in the sitemap were known to Google.
- Search Console was under-reporting. Because Google preferred the non-www copies, their clicks landed in a property nobody had. GA4 showed about 150 organic sessions a month while Search Console showed about 20 clicks.
- The site had been hacked, twice. Search Console went dark from August to December 2025. Then in April 2026 gambling spam hijacked 3 pages and pulled in 8,125 junk clicks from Indonesian slot-site searches.
- The homepage weighed 5 MB. 70 files, with single ‘thumbnail’ images over 500 KB. On a phone on safari-country data, that’s a long wait.
And then the finding that mattered most for revenue. The site was actually working for the people who found it: real visitors engaged about half the time, and about 2% of them sent an enquiry. But after the enquiry, nothing was recorded.
What I shipped
The audit took days, not weeks. The first batch of fixes went live the same week, straight into the codebase:
- Canonicals, hreflang and social tags fixed site-wide, pointing at the one true www address
- Proper titles written for 121 package pages and every blog post
- 301 redirects for the path tricks the spam used, plus the index.php duplicates
- Sitemap rebuilt around real pages and robots.txt pointed at the right one
- SQL-injection holes closed on the pages that took IDs from the URL
- GA4 events live for
private_enquiry,custom_trip_enquiry,whatsapp_clickandform_blocked - Price shown on package pages next to a pre-filled WhatsApp button
What happens next
Now every stage from Google to deposit is measured, so the next fixes are decided by numbers, not guesses. The first experiment is already running:
