Our checks catalog

Every check we run, honest about what's implemented and what's coming. All checks are passive and read-only — we never modify your site.

127 total checks 63 security 30 SEO 14 AEO

Security (63)

content integrity

sec-mixed-001 High

Mixed content

On HTTPS pages, detects resources loaded over plain HTTP which can be tampered with in transit.

A02:2021-Cryptographic Failures
sec-sri-002 Medium

Subresource integrity for third-party scripts

Checks that third-party <script> tags include an integrity attribute so the browser refuses to run tampered code from a compromised CDN.

A08:2021-Software and Data Integrity Failures

cookie session

sec-cookie-001 Medium

Cookie security attributes

Checks each cookie your site sets for the Secure, HttpOnly and SameSite attributes that stop it being stolen over plain HTTP, read by injected script, or replayed from another site.

A05:2021-Security Misconfiguration
sec-cookie-002 Medium

Cookie Secure flag

Checks that session and sensitive cookies include the Secure attribute, preventing them from being sent over unencrypted HTTP connections.

A02:2021-Cryptographic Failures
sec-cookie-003 Medium

Cookie HttpOnly flag

Checks that session cookies include HttpOnly, preventing JavaScript from reading them — the primary defence against cookie theft via XSS.

A03:2021-Injection
sec-cookie-004 Low

Cookie SameSite attribute

Checks that cookies specify a SameSite attribute (Lax or Strict), reducing exposure to CSRF attacks by controlling when the browser sends the cookie cross-site.

A01:2021-Broken Access Control
sec-cookie-005 Info

Cookie prefix compliance

Checks whether cookies use __Host- or __Secure- prefixes for maximum browser-enforced security guarantees.

A02:2021-Cryptographic Failures
sec-cookie-006 Low

Cookie size

Checks for oversized cookies that may indicate session state stored client-side, increasing request overhead and risk of truncation.

A05:2021-Security Misconfiguration
sec-csrf-001 Medium

CSRF token presence

Checks that POST forms include a hidden anti-CSRF token field, preventing cross-site request forgery attacks.

A01:2021-Broken Access Control
sec-form-003 Info

Sensitive form autocomplete

Checks whether sensitive form fields (credit card, CVV) disable autocomplete to prevent browsers from caching the values.

A04:2021-Insecure Design
sec-jwt-001 High

Weak JSON Web Token implementation

Decodes any JSON Web Tokens the site hands to the browser and reports unsigned tokens (alg none), external-key pointers (jku/x5u) and tokens that never expire.

A07:2021-Identification and Authentication Failures

cors misconfiguration

sec-cors-001 High

CORS configuration

Checks the Access-Control-Allow-Origin and Access-Control-Allow-Credentials headers for a combination that lets any website read your authenticated responses.

A01:2021-Broken Access Control
sec-cors-002 Medium

CORS wildcard origin

Checks whether the site responds with Access-Control-Allow-Origin: *, which grants every domain read access to the response.

A01:2021-Broken Access Control
sec-cors-003 High

CORS origin reflection

Sends a request with a controlled Origin header to detect whether the server echoes any origin back. Origin reflection with credentials means any website can steal user data.

A01:2021-Broken Access Control
sec-cors-004 Medium

CORS null origin allowed

Checks if the server accepts Origin: null, which allows sandboxed iframes and local HTML files to make cross-origin requests.

A01:2021-Broken Access Control
sec-cors-005 Low

CORS exposes dangerous methods

Checks if the CORS preflight response allows sensitive HTTP methods (PUT, DELETE, PATCH) or reveals internal headers that widen the attack surface.

A01:2021-Broken Access Control
sec-cors-006 Low

CORS exposed headers

Checks if Access-Control-Expose-Headers reveals sensitive internal headers to cross-origin scripts.

A01:2021-Broken Access Control

debug endpoints

sec-debug-001 High

Debug endpoint leakage

Probes common debug/diagnostics paths and detects real framework stack traces or debug pages that expose internal details to any visitor.

A05:2021-Security Misconfiguration
sec-debug-002 Medium

GraphQL introspection enabled

Checks if the GraphQL endpoint allows introspection queries, which reveal the full schema to unauthenticated users.

A01:2021-Broken Access Control
sec-debug-003 High

Debug/admin endpoints exposed

Probes for common debug, diagnostic, and administration endpoints that should never be publicly reachable.

A05:2021-Security Misconfiguration

exposed files

sec-backup-001 High

Backup files exposed

Probes for common backup and configuration files (.bak, .old, wp-config.php.bak, database dumps) that should never be publicly accessible.

A05:2021-Security Misconfiguration
sec-dirlist-001 Medium

Directory listing enabled

Detects web server autoindex / directory listing that exposes file and folder names to anyone.

A05:2021-Security Misconfiguration
sec-exposed-001 Critical

Sensitive file exposure

Probes a small list of high-signal paths for accidentally exposed sensitive files such as .env, .git/config, backup.sql, or credential stores.

A05:2021-Security Misconfiguration
sec-graphql-001 Medium

GraphQL introspection enabled

Probes common GraphQL endpoints and reports when introspection queries return the full schema, letting anyone enumerate your entire API.

A05:2021-Security Misconfiguration
sec-securitytxt-001 Info

Security.txt present

Checks for a /.well-known/security.txt file that tells security researchers how to report vulnerabilities.

sec-sourcemap-001 Medium

JavaScript source maps exposed

Checks whether the site serves source map files (.js.map) that expose original, unminified source code — potentially revealing logic, comments, and internal paths.

A05:2021-Security Misconfiguration
sec-techcve-001 Low

Outdated or disclosed frontend technology

Detects jQuery versions with known XSS vulnerabilities and WordPress/version disclosures that make targeted attacks easier.

A06:2021-Vulnerable and Outdated Components
sec-vcs-001 High

Version control directories

Probes for exposed .svn/entries or .hg/store paths that could leak source code history.

A05:2021-Security Misconfiguration
sec-wellknown-001 Medium

Sensitive .well-known paths

Probes for .well-known paths that may expose internal configuration, such as openid-configuration or jwks.json endpoints that should be restricted.

A01:2021-Broken Access Control

secret exposure

sec-baas-001 Medium

Backend-as-a-service configuration exposed

Looks for Supabase project URLs / anon keys and Firebase config objects shipped in client code, and flags the row-level-security / rules review they demand.

A01:2021-Broken Access Control
sec-jssecrets-001 High

API key exposed in JavaScript bundle

Fetches the site's own JavaScript bundles and scans them for live third-party API keys and hardcoded credentials that any visitor can read.

A02:2021-Cryptographic Failures
sec-secrets-001 Critical

API key exposure in HTML

Scans served HTML and inline scripts for high-confidence API key patterns (Stripe, OpenAI, AWS, Google, Supabase, Firebase, PEM private keys) and distinguishes publishable keys from secret keys.

A01:2021-Broken Access Control
sec-secrets-002 High

API keys in HTML source

Scans the page's HTML source for patterns matching common API keys and tokens that should never be client-visible.

A02:2021-Cryptographic Failures

security headers

sec-cache-001 Low

Cache-Control for sensitive pages

Checks that the page sends Cache-Control headers that prevent intermediary caches from storing potentially sensitive content.

A05:2021-Security Misconfiguration
sec-coep-001 Info

Cross-origin isolation headers

Checks for Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy headers that provide cross-origin isolation, mitigating Spectre-class side-channel attacks.

A05:2021-Security Misconfiguration
sec-corp-001 Info

Cross-Origin-Resource-Policy

Checks for a Cross-Origin-Resource-Policy header that explicitly limits which origins can load this resource, protecting against cross-origin data exfiltration.

A05:2021-Security Misconfiguration
sec-crlf-001 Info

Response header injection indicators

Checks for unusual characters in response headers that may indicate response splitting vulnerabilities.

A03:2021-Injection
sec-csp-001 Medium

Content Security Policy present

Checks whether the page sends a Content-Security-Policy header, the primary browser-side defence against cross-site scripting and injected third-party code.

A03:2021-Injection
sec-csp-002 Medium

Content Security Policy strength

Inspects an existing Content-Security-Policy for directives that neutralise it, such as unsafe-inline, unsafe-eval, or a wildcard script source.

A03:2021-Injection
sec-csp-003 Info

CSP strict-dynamic support

Checks if a nonce-based CSP also includes 'strict-dynamic' for better compatibility with dynamically-loaded scripts.

A03:2021-Injection
sec-disclosure-001 Low

Software version disclosure

Looks for response headers that publish your exact server or framework version, which lets an attacker look up known vulnerabilities for that build without probing.

A05:2021-Security Misconfiguration
sec-frame-001 Medium

Clickjacking protection

Checks that the page restricts framing through CSP frame-ancestors or X-Frame-Options, so it cannot be embedded invisibly over an attacker's page.

A05:2021-Security Misconfiguration
sec-hsts-001 Medium

HTTP Strict Transport Security

Checks that HTTPS responses send a Strict-Transport-Security header with a long enough max-age, so browsers refuse to fall back to plain HTTP.

A05:2021-Security Misconfiguration
sec-iframe-001 Low

Iframe sandbox attribute

Checks that embedded iframes use the sandbox attribute to restrict their capabilities (script execution, form submission, navigation).

A05:2021-Security Misconfiguration
sec-ipleak-001 Low

Internal IP address disclosure

Checks whether response headers reveal internal/private IP addresses, which exposes infrastructure topology to attackers.

A01:2021-Broken Access Control
sec-permissions-001 Info

Permissions policy

Checks for a Permissions-Policy header limiting which powerful features (camera, microphone, geolocation, payment) your page and its embedded frames may use.

A05:2021-Security Misconfiguration
sec-privacy-001 Info

Privacy headers

Checks for privacy-related response headers like Tk (Tracking Status) that acknowledge Do Not Track preferences.

sec-referrer-001 Low

Referrer policy

Checks whether a Referrer-Policy prevents full URLs — which often contain tokens or identifiers — from leaking to third-party sites.

A01:2021-Broken Access Control
sec-server-001 Low

Verbose Server header

Checks if the Server header contains OS or detailed build information beyond the product name.

A05:2021-Security Misconfiguration
sec-sqlerr-001 Medium

Database error message exposed

Scans the served page for raw database error strings (MySQL, PostgreSQL, SQL Server, Oracle, SQLite) that leak query and schema details to attackers.

A05:2021-Security Misconfiguration
sec-tabnab-001 Low

Tab-nabbing protection

Checks that links with target=_blank include rel=noopener to prevent reverse tabnabbing attacks.

A04:2021-Insecure Design
sec-xcto-001 Low

MIME type sniffing protection

Checks for X-Content-Type-Options: nosniff, which stops browsers from guessing a response's type and executing an upload as script.

A05:2021-Security Misconfiguration
sec-xss-001 Medium

DOM XSS sinks in inline scripts

Scans inline scripts for dangerous DOM manipulation patterns (innerHTML, document.write, eval) that can lead to DOM-based XSS if fed user input.

A03:2021-Injection

ssl tls

sec-ct-001 Info

Certificate Transparency

Checks whether the site sends an Expect-CT header to enforce Certificate Transparency logging, making it harder for misissued certificates to go unnoticed.

A02:2021-Cryptographic Failures
sec-hpkp-001 Medium

HPKP header residue

Detects the deprecated Public-Key-Pins header which can brick a site if keys are rotated without updating pins.

A05:2021-Security Misconfiguration
sec-tls-001 High

TLS certificate validity

Performs a TLS handshake and reports whether the certificate chain and hostname validate, and how much runway is left before it expires.

A02:2021-Cryptographic Failures
sec-tls-002 Medium

TLS protocol version

Reports which TLS version the server negotiated. TLS 1.0 and 1.1 are deprecated and rejected by current browsers.

A02:2021-Cryptographic Failures

transport security

sec-form-001 High

Form action over HTTPS

Checks that form actions don't submit data over plain HTTP when the page is HTTPS, which would expose credentials and form data.

A02:2021-Cryptographic Failures
sec-form-002 Critical

Password input over HTTPS

Checks that pages with password inputs are served over HTTPS.

A02:2021-Cryptographic Failures
sec-form-004 Medium

Cross-domain form submission

Detects forms that POST data to a different domain, which may indicate data exfiltration or misconfigured third-party integrations.

A04:2021-Insecure Design
sec-https-001 High

HTTPS enforcement

Checks that the site is served over HTTPS. Content delivered over plain HTTP can be read and modified by anyone on the network path.

A02:2021-Cryptographic Failures
sec-openredirect-001 High

Open redirect

Tests common redirect parameters with an external marker URL to find redirects that will send your users to any attacker-chosen site.

A01:2021-Broken Access Control
sec-takeover-001 High

Subdomain takeover indicator

Checks the response body for error messages that indicate the domain points to an unclaimed third-party service (GitHub Pages, S3, Heroku, etc.), enabling subdomain takeover.

A05:2021-Security Misconfiguration

Seo (30)

seo

seo-canonical-001 Medium

Canonical link

Checks for a <link rel="canonical"> that tells search engines which URL is the definitive version of this page.

seo-canonical-002 Info

Canonical self-reference

Checks that the canonical link, when present, points to the page's own URL (self-referencing) or a clearly intended alternative.

seo-charset-001 Medium

Character encoding

Checks that the page declares its character encoding (ideally UTF-8) early in the document, preventing garbled text and crawl issues.

seo-dupmeta-001 Medium

Duplicate meta tags

Checks for multiple <title> or <meta name='description'> elements, which confuses search engines about which to use.

seo-extlink-001 Low

External link rel attributes

Checks that external links with target=_blank include rel="noopener" to prevent the linked page from accessing window.opener.

seo-favicon-001 Low

Favicon present

Checks that the page declares a favicon, which appears in browser tabs, bookmarks, and search results.

seo-h1-001 Medium

H1 heading

Checks that the page has exactly one H1 heading, establishing a clear topic for both users and search engines.

seo-headings-001 Low

Heading hierarchy

Checks that headings follow a logical hierarchy (h1→h2→h3) without skipping levels, which helps both SEO and accessibility.

seo-imgalt-001 Low

Image alt text

Reports images without alt attributes, which hurts accessibility and prevents search engines from understanding image content.

seo-imgdim-001 Low

Image dimensions specified

Checks that <img> elements include explicit width and height attributes, preventing layout shift (CLS) and improving Core Web Vitals scores.

seo-jsonld-001 Medium

JSON-LD validity

Checks that any JSON-LD structured data on the page is valid JSON and contains the required @type property.

seo-lang-001 Medium

HTML lang attribute

Checks that the <html> element declares a language, helping search engines and screen readers process the content correctly.

seo-linktext-001 Low

Descriptive link text

Checks that links use descriptive anchor text instead of generic phrases like 'click here', which harms both SEO and accessibility.

seo-metadesc-001 Medium

Meta description

Checks for a meta description within the recommended length range for search result snippets.

seo-nofollow-001 Low

Nofollow usage

Checks whether internal links are accidentally marked nofollow, which wastes link equity and hurts internal page authority.

seo-noindex-001 High

Noindex directive

Checks for a noindex meta tag or X-Robots-Tag header that prevents search engines from indexing the page.

seo-og-001 Medium

Open Graph tags

Checks for essential Open Graph meta tags (og:title, og:description, og:image) that control how links appear when shared on social media.

seo-og-002 Low

Open Graph image dimensions

Checks that og:image includes width and height meta tags, which helps platforms render previews without loading the image first.

seo-renderblock-001 Low

Render-blocking resources

Checks for render-blocking JavaScript and CSS in the <head> that delay First Contentful Paint, hurting Core Web Vitals and search rankings.

seo-robots-001 High

Robots.txt blocking all crawlers

Checks if robots.txt contains a blanket Disallow: / for all user agents, which prevents all search engine indexing.

seo-robotsquality-001 Low

Robots.txt quality

Checks that robots.txt exists, is valid, and contains useful directives beyond just allowing everything.

seo-sitemap-001 Medium

XML sitemap

Checks for a sitemap.xml file that helps search engines discover and prioritize pages on your site.

seo-status-001 Medium

HTTP status code

Checks that the page returns an appropriate 2xx status code and doesn't use soft redirects or error pages that return 200.

seo-taptarget-001 Low

Tap target sizing

Checks for inline styles or CSS that make interactive elements too small for comfortable mobile tapping (< 44x44px).

seo-thincontent-001 Medium

Content depth

Checks that the page has sufficient text content (>100 words) to be considered substantive by search engines.

seo-title-001 High

Page title

Checks that the page has a <title> element within the recommended length range for search result display.

seo-twitter-001 Low

Twitter Card tags

Checks for Twitter/X Card meta tags that control how the page appears when shared on Twitter/X.

seo-url-001 Low

URL structure

Checks that the page URL is clean, descriptive, and free of excessive parameters or cryptic IDs that harm SEO.

seo-viewport-001 High

Viewport meta tag

Checks for a viewport meta tag, which is required for mobile-friendly rendering and affects mobile search rankings.

seo-xrobots-001 High

X-Robots-Tag header

Checks whether the server sends an X-Robots-Tag header that blocks indexing (noindex) or following links (nofollow), which may be unintentional in production.

Aeo (14)

aeo

aeo-answers-001 Low

Answer-shaped headings

Checks whether the page uses question-style or clear topic headings that AI systems can identify and extract as direct answers to user queries.

aeo-citation-001 Low

Citation readiness

Checks for authorship, organization, and publication date signals that AI systems use when deciding whether and how to cite content in generated answers.

aeo-crawlbudget-001 Info

AI crawler crawl budget

Checks whether AI crawlers are given appropriate crawl-delay or rate limits in robots.txt to manage server load without blocking them entirely.

aeo-crawlers-001 Medium

AI crawler access in robots.txt

Checks whether robots.txt explicitly blocks major AI crawlers, which prevents your content from appearing in AI-generated answers.

aeo-crawlers-002 Info

AI crawler access granularity

Examines robots.txt for granular AI crawler directives — reports which AI crawlers are explicitly blocked or allowed, helping site owners make informed visibility decisions.

aeo-entity-001 Medium

Entity/brand clarity

Checks that the page clearly identifies what entity (brand, person, organization) is behind the content, which AI systems use for attribution and trust signals.

aeo-extractable-001 Medium

Content extractable without JS

Checks whether the page's main content is present in the initial HTML response, since AI crawlers and answer engines typically cannot execute JavaScript.

aeo-faq-001 Low

FAQ structured data

Checks for FAQPage or QAPage schema markup that helps AI systems identify and extract question-answer pairs from your content.

aeo-freshness-001 Low

Content freshness signals

Checks for Last-Modified headers and dateModified schema properties that signal content currency to AI systems.

aeo-howto-001 Info

HowTo structured data

Checks for HowTo schema on pages that contain step-by-step instructions, which helps AI systems extract procedural knowledge.

aeo-llmstxt-001 Info

llms.txt presence

Checks whether the site publishes an /llms.txt file that helps AI systems understand what content is available for extraction.

aeo-semantic-001 Low

Semantic HTML landmarks

Checks for semantic HTML5 landmark elements (main, article, nav, header) that help AI systems identify and extract meaningful content regions.

aeo-structdata-001 Medium

Structured data (JSON-LD)

Checks for application/ld+json script blocks containing structured data, and whether the JSON is valid.

aeo-summary-001 Low

Content summarizability

Checks whether the page's first paragraph provides a clear, concise summary that AI systems can extract as a direct answer or featured snippet.

Performance (12)

caching

perf-cache-001 Low

Browser caching headers

Checks that the HTML response includes Cache-Control, ETag or Last-Modified so browsers and CDNs can avoid re-downloading unchanged content.

compression

perf-compress-001 Low

Text compression

Checks that the HTML document is served gzip- or brotli-compressed, which typically cuts transfer size by 60-80%.

dom size

perf-domsize-001 Low

Excessive DOM size

Counts the page's DOM nodes and flags pages far past the ~800-node depth where style recalculation and reflow costs start to bite.

fonts

perf-fonts-001 Low

Font display not specified

Checks @font-face rules for a font-display strategy so text renders immediately instead of waiting on slow font downloads.

images

perf-lazyimg-001 Low

Images not lazy-loaded

Checks that image-heavy pages use loading="lazy" so off-screen images don't compete with the content the visitor actually sees first.

perf-modernimg-001 Low

Images not served in modern formats

Flags pages serving several JPEG/PNG images with no WebP/AVIF anywhere — typically about twice the image bytes visitors must download.

perf-srcset-001 Low

No responsive image variants

Checks that image-heavy pages provide srcset variants so mobile visitors download mobile-sized images instead of desktop originals.

page weight

perf-weight-001 Medium

HTML document size

Checks the transferred size of the HTML document itself. Bloated HTML delays first paint and eats mobile data budgets.

redirects

perf-redirects-001 Low

Redirect chain length

Counts the HTTP redirects a visitor's browser follows before receiving the page. Each hop adds a full round trip before any content loads.

render blocking

perf-renderblock-001 Medium

Render-blocking resources

Counts stylesheets and synchronous scripts in the document head. Each one blocks the browser from painting anything until it downloads.

resource hints

perf-hints-001 Low

Missing resource hints for third-party origins

Checks that pages loading assets from third-party origins declare preconnect / dns-prefetch hints so the browser can warm those connections early.

response time

perf-ttfb-001 Medium

Server response time

Measures how long the server takes to deliver the HTML document. Slow servers push back every other improvement a visitor experiences.

Compliance (2)

cookie consent

comp-cookiebanner-001 Medium

Cookie consent banner

Checks the page's initial HTML for a recognisable cookie-consent banner or consent-management-platform script.

privacy disclosure

comp-privacylink-001 Medium

Privacy policy link

Checks that the page links to a privacy policy somewhere in the document.

Accessibility (1)

wcag axecore

a11y-axecore-001 Medium

WCAG accessibility violation

Runs the axe-core accessibility engine against the live, rendered page (including same-origin and cross-origin iframes) and reports WCAG rule violations.

Email (2)

dmarc

email-dmarc-001 Medium

DMARC record

Checks for a DMARC policy record at _dmarc.{domain}, which tells receiving mail servers what to do with mail that fails SPF/DKIM authentication.

spf

email-spf-001 Medium

SPF record

Checks for a valid Sender Policy Framework (SPF) TXT record, which tells receiving mail servers which hosts are authorized to send email for this domain.

Domain (3)

dnssec

domain-dnssec-001 Low

DNSSEC not signed

Checks whether the domain's delegation is DNSSEC-signed, via RDAP secureDNS.delegationSigned.

expiry

domain-expiry-001 Medium

Domain registration expiry

Checks how much time remains before the domain's registration expires, via RDAP.

transfer lock

domain-transfer-lock-001 Medium

Registrar transfer lock

Checks whether the domain has a registrar transfer-prohibited lock (EPP status) set, via RDAP.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.