SCANNERS ONLINE / 127 CHECKS PER PASS / MEDIAN RUNTIME 38.4s LAST INDEX SYNC 00:04:12 AGO
Coverage Findings Replaces Pricing FAQ
Auto-fix · one click

127 checks find it. One click fixes it.

Every finding goes to AI auto-fix agents. They write the patch, cross-check it against your code, and deliver it as a pull request on your GitHub repo. Nothing is merged without your approval.

01 · Find
127checks in every pass
  • Security63
  • SEO30
  • AI search (AEO)14
  • Performance12
  • Domain & TLS3
  • Email auth2
  • Compliance2
  • Accessibility1
02 · Fix
  • GPT-6 Astra · Opus 5.5 · GLM 5.3 · GLM 5.3 Flash
  • Podman sandbox
  • PR-ready patches

Works through the Claude Code CLI harness

03 · Ship
GitHub pull requestFixes land on a new branch as a PR you review and merge.
Fix promptsEvery finding compiles into a paste-ready prompt for your coding agent.
Human reviewNothing is merged or deployed without your approval.
Every scan covers Live site · 127 checksRepo · CodeQL deep analysisContainer images Reserve your spot →
Pre-launch · reserve your spot

Security, SEO & AI visibility,
scanned in one pass.

Findings ranked by what to fix first — 127 checks across eight pillars (security, SEO, AI search, performance, domain, email, compliance and accessibility), then one click sends the findings to AI auto-fix agents that open a pull request on your repo.

Reserve your spot

Join The WaitList - Launching in Four Days

Free during launch week. One email at launch — no spam.

38.4smedian runtime
8audit pillars
127checks per pass
sitehealthscan.com · run/8f2c41 · your-app.dev SCANNING
4
criticals found
SURFACE MAP · 41 ROUTES · 12 ORIGINS
82
SEC
67
SEO
45
AEO
91
PERF
CSP header policyRLS policy gaps.env leakage in bundle CORS wildcard originsJWT expiry + algorithmCore Web Vitals robots.txt AI crawler rulesllms.txt presenceschema.org coverage TLS chain + expiryDNSSECopen redirects SQLi probe surfacecookie consent signalsWCAG contrastCSP header policyRLS policy gaps.env leakage in bundle CORS wildcard originsJWT expiry + algorithmCore Web Vitals robots.txt AI crawler rulesllms.txt presenceschema.org coverage TLS chain + expiryDNSSECopen redirects SQLi probe surfacecookie consent signalsWCAG contrast
01coverage.map 8 PILLARS · 127 CHECKS

Eight pillars. One pass.

Every pillar runs against your live site in parallel. Nothing installed, nothing written, nothing submitted — read-only probes of what the public internet can already reach.

P01 / SECURITY82/100

Security

Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.

63 CHECKS3 open
P02 / SEO67/100

Search

Crawlability, sitemap and canonical integrity, metadata completeness, internal link graph, index eligibility per route.

30 CHECKS11 open
P03 / AEO45/100

AI visibility

Whether answer engines can parse, trust and cite you. Structured data coverage, llms.txt, crawler permissions, claim extractability.

14 CHECKS19 open
P04 / PERF91/100

Performance

Core Web Vitals under throttled conditions, bundle weight, render-blocking chains, image and font delivery.

12 CHECKS1 open
P05 / WATCH24/7

Monitoring

Sixty-second uptime probes, certificate and domain expiry runway, live attack telemetry, score-drift alerts.

CONTINUOUSarmed
P06 / LEGAL78/100

Domain, email & compliance

Domain and TLS expiry, DNSSEC, SPF/DKIM/DMARC, cookie consent, privacy and terms presence, WCAG contrast and semantics.

8 CHECKS6 open
02findings.ranked SORTED BY BLAST RADIUS

Ranked by what actually breaks trust.

Not an alphabetised wall of warnings. Findings are ordered by what a real attacker or a real crawler reaches first — and each one carries a fix you can paste straight into your coding agent.

RUN 8F2C41 YOUR-APP.DEV 40 FINDINGS · 4 CRITICAL
01
critical
Supabase service-role key reachable in client bundle /_app/immutable/chunks/
SECURITY
Auto-fix →
02
critical
Row-level security disabled on public.profiles — full table readable
SECURITY
Auto-fix →
03
critical
Wildcard CORS Access-Control-Allow-Origin: * on authenticated routes
SECURITY
Auto-fix →
04
warning
No llms.txt — answer engines have no citation policy to follow
AEO
Auto-fix →
05
warning
Structured data absent on 34 of 41 indexable routes
AEO
Auto-fix →
06
warning
Content-Security-Policy missing frame-ancestors directive
SECURITY
Auto-fix →
07
passed
TLS chain valid, 74 days of runway remaining
SECURITY
—
36 further findings — including 1 remaining critical — are held behind the free tier. Unlock the full report →
03pipeline.seq PASTE → SCAN → PATCH

Three steps, and one of them is pasting a URL.

STEP 01
◦

Point it at the site

Production, staging, or the thing you built on a Sunday. Optionally connect GitHub and your database for a deeper pass at the code behind it.

STEP 02
◈

127 checks run in parallel

Six pillars execute at once against the live surface. Median wall-clock time is under forty seconds, including a full crawl and a throttled vitals run.

STEP 03
◆

Hand the fixes to your agent

Every finding compiles into a prompt with file paths and context. Paste it into Claude Code, Cursor or Codex — or let an auto-fix pull request land on GitHub.

04stack.replace EIGHT TABS → ONE

What you're currently doing in eight tabs.

Most teams stitch this together from a header checker, a Lighthouse run, an uptime pinger and a lot of hoping. Here's the same coverage in one pass.

Capability SiteHealthScan.com Header checkers Lighthouse Uptime pingers
Security headers & CSPsurface config■ full■ full□ none□ none
Exposed secrets in bundleclient-side leakage■ full□ none□ none□ none
Database policy gapsRLS & row exposure■ full□ none□ none□ none
Core Web Vitalsthrottled field run■ full□ none■ full□ none
Technical SEO crawlsitemap, canonical, meta■ full□ none▪ partial□ none
AI answer-engine visibilitycitation eligibility■ full□ none□ none□ none
Continuous monitoringuptime & score drift■ full□ none□ none▪ uptime only
Paste-ready remediationagent-executable■ full□ none□ none□ none
REST API + auto-fix PRspipe into your agent■ full□ none▪ CLI only▪ webhook
One-click AI auto-fixDelivered as a GitHub PR■ full□ none□ none□ none
Repo & container deep scanCodeQL analysis and image scanning■ full□ none□ none□ none
05telemetry.live HISTORY IS KEPT

Watch it get better.

Every scan is retained and diffed. When a deploy quietly regresses your score, you hear about it from us — not from a customer.

88 ▲ 31 pts since first scan OVERALL HEALTH · 90 DAYS
DAY 01 · 57DAY 30DAY 60TODAY · 88
zsh — sitehealthscan mcp
$ claude mcp add sitehealthscan
✓ connected · 26 tools exposed
> scan your-app.dev --fix
running 127 checks ······· 38.4s
✗ 4 critical · 12 warning
patching 3 files ········· done
$
06plans.json CANCEL ANY TIME

The scan is free. The fixes aren't.

Your first scans are free (3 a day) with your score and critical count. Paid plans open every finding, one-click auto-fix and continuous monitoring.

Recon

See where you stand. No card, no expiry.

$0
FOREVER
  • 3 scans a day on 1 site
  • All eight pillar scores
  • Critical count and severity split
  • Top 4 findings in full
Reserve my spot
◆ most chosen

Operator

The full report, plus a fix for every line of it.

$29/mo
PER MONTH · CANCEL ANYTIME
  • Every finding, fully detailed
  • GitHub auto-fix pull requests, 20 a month
  • Up to 5 sites, scheduled re-scans
  • Daily monitoring with drift alerts
  • PDF and Markdown exports
Unlock the report →

Command

For agencies shipping other people's sites.

$59/mo
PER MONTH · CANCEL ANYTIME
  • Everything in Operator
  • 25 sites, custom schedules, API access
  • Governance policies across every project
  • Priority support and onboarding
  • Client-ready PDF reports
Talk to us

Every plan, one ladder

Annual billing saves 20%. Need more than 25 seats, a DPA or invoicing? Enterprise is a conversation, not a form.

  • New: team plans with seats and invites
  • New: SIEM-ready findings export (NDJSON)
  • New: scan any site from your CI with the REST API
  • New: plan-based project, scan and API-key limits you can see
07questions.md THE HONEST ANSWERS

Before you paste the URL.

Q1Is it safe to run against a live production site?+
Yes. Every check is a read-only probe of something already publicly reachable. Nothing is written, submitted, mutated or stored on your side. The scan looks like ordinary traffic — a crawler and a handful of header requests.
Q2What is AEO, and why does it have its own pillar?+
Answer Engine Optimisation. People increasingly ask ChatGPT, Claude or Perplexity what tool to use rather than typing into a search box. AEO checks whether those systems can reach your content, parse a clear claim out of it, and cite you. It fails differently from SEO, so it gets scored separately.
Q3Do I need to install anything or change my code?+
No. Paste a URL and the scan runs against the live surface. Connecting your repository or database is optional and only widens what we can see — it is never required for a score.
Q4What exactly does a "fix prompt" contain?+
The finding, the affected file paths or routes, the relevant framework context, and the change to make — written to be pasted directly into a coding agent. Paid plans can open an auto-fix pull request on GitHub instead of handing you text.
Q5Will a bad score be shown publicly?+
Never by default. Reports are private to your account. There is an opt-in public leaderboard for builders who want to show a clean score — it is off unless you switch it on, and it can be switched back off at any time.
Q6How does one-click auto-fix work?+
Pick the findings you want fixed, or all of them, and click Auto-fix. AI auto-fix agents write and cross-check the patch, then deliver it as a pull request on your GitHub repo. Nothing is merged without your approval.
Q7Do you offer team plans?+
Yes. Team Basic ($19 per seat per month) and Team Advanced ($39 per seat per month), both with a 5-seat minimum sold in blocks of 5, add pooled scans, shared team projects and member invites — Team Advanced also includes SIEM log export. See Pricing for the full comparison.

Find it before
somebody else does.

Launching in four days. Reserve your spot and your first scan runs the moment we open.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.