Security
Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.
Every finding goes to AI auto-fix agents. They write the patch, cross-check it against your code, and deliver it as a pull request on your GitHub repo. Nothing is merged without your approval.
Works through the Claude Code CLI harness
Findings ranked by what to fix first — 127 checks across eight pillars (security, SEO, AI search, performance, domain, email, compliance and accessibility), then one click sends the findings to AI auto-fix agents that open a pull request on your repo.
Join The WaitList - Launching in Four Days
Free during launch week. One email at launch — no spam.
Every pillar runs against your live site in parallel. Nothing installed, nothing written, nothing submitted — read-only probes of what the public internet can already reach.
Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.
Crawlability, sitemap and canonical integrity, metadata completeness, internal link graph, index eligibility per route.
Whether answer engines can parse, trust and cite you. Structured data coverage, llms.txt, crawler permissions, claim extractability.
Core Web Vitals under throttled conditions, bundle weight, render-blocking chains, image and font delivery.
Sixty-second uptime probes, certificate and domain expiry runway, live attack telemetry, score-drift alerts.
Domain and TLS expiry, DNSSEC, SPF/DKIM/DMARC, cookie consent, privacy and terms presence, WCAG contrast and semantics.
Not an alphabetised wall of warnings. Findings are ordered by what a real attacker or a real crawler reaches first — and each one carries a fix you can paste straight into your coding agent.
/_app/immutable/chunks/public.profiles — full table readableAccess-Control-Allow-Origin: * on authenticated routesllms.txt — answer engines have no citation policy to followProduction, staging, or the thing you built on a Sunday. Optionally connect GitHub and your database for a deeper pass at the code behind it.
Six pillars execute at once against the live surface. Median wall-clock time is under forty seconds, including a full crawl and a throttled vitals run.
Every finding compiles into a prompt with file paths and context. Paste it into Claude Code, Cursor or Codex — or let an auto-fix pull request land on GitHub.
Most teams stitch this together from a header checker, a Lighthouse run, an uptime pinger and a lot of hoping. Here's the same coverage in one pass.
| Capability | SiteHealthScan.com | Header checkers | Lighthouse | Uptime pingers |
|---|---|---|---|---|
| Security headers & CSPsurface config | ■ full | ■ full | □ none | □ none |
| Exposed secrets in bundleclient-side leakage | ■ full | □ none | □ none | □ none |
| Database policy gapsRLS & row exposure | ■ full | □ none | □ none | □ none |
| Core Web Vitalsthrottled field run | ■ full | □ none | ■ full | □ none |
| Technical SEO crawlsitemap, canonical, meta | ■ full | □ none | ▪ partial | □ none |
| AI answer-engine visibilitycitation eligibility | ■ full | □ none | □ none | □ none |
| Continuous monitoringuptime & score drift | ■ full | □ none | □ none | ▪ uptime only |
| Paste-ready remediationagent-executable | ■ full | □ none | □ none | □ none |
| REST API + auto-fix PRspipe into your agent | ■ full | □ none | ▪ CLI only | ▪ webhook |
| One-click AI auto-fixDelivered as a GitHub PR | ■ full | □ none | □ none | □ none |
| Repo & container deep scanCodeQL analysis and image scanning | ■ full | □ none | □ none | □ none |
Every scan is retained and diffed. When a deploy quietly regresses your score, you hear about it from us — not from a customer.
Your first scans are free (3 a day) with your score and critical count. Paid plans open every finding, one-click auto-fix and continuous monitoring.
See where you stand. No card, no expiry.
The full report, plus a fix for every line of it.
For agencies shipping other people's sites.
Every plan, one ladder
Annual billing saves 20%. Need more than 25 seats, a DPA or invoicing? Enterprise is a conversation, not a form.
Launching in four days. Reserve your spot and your first scan runs the moment we open.