Every check we run, honest about what's implemented and what's coming. All checks are passive and read-only — we never modify your site.
On HTTPS pages, detects resources loaded over plain HTTP which can be tampered with in transit.
A02:2021-Cryptographic FailuresChecks that third-party <script> tags include an integrity attribute so the browser refuses to run tampered code from a compromised CDN.
A08:2021-Software and Data Integrity FailuresChecks each cookie your site sets for the Secure, HttpOnly and SameSite attributes that stop it being stolen over plain HTTP, read by injected script, or replayed from another site.
A05:2021-Security MisconfigurationChecks that session and sensitive cookies include the Secure attribute, preventing them from being sent over unencrypted HTTP connections.
A02:2021-Cryptographic FailuresChecks that session cookies include HttpOnly, preventing JavaScript from reading them — the primary defence against cookie theft via XSS.
A03:2021-InjectionChecks that cookies specify a SameSite attribute (Lax or Strict), reducing exposure to CSRF attacks by controlling when the browser sends the cookie cross-site.
A01:2021-Broken Access ControlChecks whether cookies use __Host- or __Secure- prefixes for maximum browser-enforced security guarantees.
A02:2021-Cryptographic FailuresChecks for oversized cookies that may indicate session state stored client-side, increasing request overhead and risk of truncation.
A05:2021-Security MisconfigurationChecks that POST forms include a hidden anti-CSRF token field, preventing cross-site request forgery attacks.
A01:2021-Broken Access ControlChecks whether sensitive form fields (credit card, CVV) disable autocomplete to prevent browsers from caching the values.
A04:2021-Insecure DesignDecodes any JSON Web Tokens the site hands to the browser and reports unsigned tokens (alg none), external-key pointers (jku/x5u) and tokens that never expire.
A07:2021-Identification and Authentication FailuresChecks the Access-Control-Allow-Origin and Access-Control-Allow-Credentials headers for a combination that lets any website read your authenticated responses.
A01:2021-Broken Access ControlChecks whether the site responds with Access-Control-Allow-Origin: *, which grants every domain read access to the response.
A01:2021-Broken Access ControlSends a request with a controlled Origin header to detect whether the server echoes any origin back. Origin reflection with credentials means any website can steal user data.
A01:2021-Broken Access ControlChecks if the server accepts Origin: null, which allows sandboxed iframes and local HTML files to make cross-origin requests.
A01:2021-Broken Access ControlChecks if the CORS preflight response allows sensitive HTTP methods (PUT, DELETE, PATCH) or reveals internal headers that widen the attack surface.
A01:2021-Broken Access ControlChecks if Access-Control-Expose-Headers reveals sensitive internal headers to cross-origin scripts.
A01:2021-Broken Access ControlProbes common debug/diagnostics paths and detects real framework stack traces or debug pages that expose internal details to any visitor.
A05:2021-Security MisconfigurationChecks if the GraphQL endpoint allows introspection queries, which reveal the full schema to unauthenticated users.
A01:2021-Broken Access ControlProbes for common debug, diagnostic, and administration endpoints that should never be publicly reachable.
A05:2021-Security MisconfigurationProbes for common backup and configuration files (.bak, .old, wp-config.php.bak, database dumps) that should never be publicly accessible.
A05:2021-Security MisconfigurationDetects web server autoindex / directory listing that exposes file and folder names to anyone.
A05:2021-Security MisconfigurationProbes a small list of high-signal paths for accidentally exposed sensitive files such as .env, .git/config, backup.sql, or credential stores.
A05:2021-Security MisconfigurationProbes common GraphQL endpoints and reports when introspection queries return the full schema, letting anyone enumerate your entire API.
A05:2021-Security MisconfigurationChecks for a /.well-known/security.txt file that tells security researchers how to report vulnerabilities.
Checks whether the site serves source map files (.js.map) that expose original, unminified source code — potentially revealing logic, comments, and internal paths.
A05:2021-Security MisconfigurationDetects jQuery versions with known XSS vulnerabilities and WordPress/version disclosures that make targeted attacks easier.
A06:2021-Vulnerable and Outdated ComponentsProbes for exposed .svn/entries or .hg/store paths that could leak source code history.
A05:2021-Security MisconfigurationProbes for .well-known paths that may expose internal configuration, such as openid-configuration or jwks.json endpoints that should be restricted.
A01:2021-Broken Access ControlLooks for Supabase project URLs / anon keys and Firebase config objects shipped in client code, and flags the row-level-security / rules review they demand.
A01:2021-Broken Access ControlFetches the site's own JavaScript bundles and scans them for live third-party API keys and hardcoded credentials that any visitor can read.
A02:2021-Cryptographic FailuresScans served HTML and inline scripts for high-confidence API key patterns (Stripe, OpenAI, AWS, Google, Supabase, Firebase, PEM private keys) and distinguishes publishable keys from secret keys.
A01:2021-Broken Access ControlScans the page's HTML source for patterns matching common API keys and tokens that should never be client-visible.
A02:2021-Cryptographic FailuresChecks that the page sends Cache-Control headers that prevent intermediary caches from storing potentially sensitive content.
A05:2021-Security MisconfigurationChecks for Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy headers that provide cross-origin isolation, mitigating Spectre-class side-channel attacks.
A05:2021-Security MisconfigurationChecks for a Cross-Origin-Resource-Policy header that explicitly limits which origins can load this resource, protecting against cross-origin data exfiltration.
A05:2021-Security MisconfigurationChecks for unusual characters in response headers that may indicate response splitting vulnerabilities.
A03:2021-InjectionChecks whether the page sends a Content-Security-Policy header, the primary browser-side defence against cross-site scripting and injected third-party code.
A03:2021-InjectionInspects an existing Content-Security-Policy for directives that neutralise it, such as unsafe-inline, unsafe-eval, or a wildcard script source.
A03:2021-InjectionChecks if a nonce-based CSP also includes 'strict-dynamic' for better compatibility with dynamically-loaded scripts.
A03:2021-InjectionLooks for response headers that publish your exact server or framework version, which lets an attacker look up known vulnerabilities for that build without probing.
A05:2021-Security MisconfigurationChecks that the page restricts framing through CSP frame-ancestors or X-Frame-Options, so it cannot be embedded invisibly over an attacker's page.
A05:2021-Security MisconfigurationChecks that HTTPS responses send a Strict-Transport-Security header with a long enough max-age, so browsers refuse to fall back to plain HTTP.
A05:2021-Security MisconfigurationChecks that embedded iframes use the sandbox attribute to restrict their capabilities (script execution, form submission, navigation).
A05:2021-Security MisconfigurationChecks whether response headers reveal internal/private IP addresses, which exposes infrastructure topology to attackers.
A01:2021-Broken Access ControlChecks for a Permissions-Policy header limiting which powerful features (camera, microphone, geolocation, payment) your page and its embedded frames may use.
A05:2021-Security MisconfigurationChecks for privacy-related response headers like Tk (Tracking Status) that acknowledge Do Not Track preferences.
Checks whether a Referrer-Policy prevents full URLs — which often contain tokens or identifiers — from leaking to third-party sites.
A01:2021-Broken Access ControlChecks if the Server header contains OS or detailed build information beyond the product name.
A05:2021-Security MisconfigurationScans the served page for raw database error strings (MySQL, PostgreSQL, SQL Server, Oracle, SQLite) that leak query and schema details to attackers.
A05:2021-Security MisconfigurationChecks that links with target=_blank include rel=noopener to prevent reverse tabnabbing attacks.
A04:2021-Insecure DesignChecks for X-Content-Type-Options: nosniff, which stops browsers from guessing a response's type and executing an upload as script.
A05:2021-Security MisconfigurationScans inline scripts for dangerous DOM manipulation patterns (innerHTML, document.write, eval) that can lead to DOM-based XSS if fed user input.
A03:2021-InjectionChecks whether the site sends an Expect-CT header to enforce Certificate Transparency logging, making it harder for misissued certificates to go unnoticed.
A02:2021-Cryptographic FailuresDetects the deprecated Public-Key-Pins header which can brick a site if keys are rotated without updating pins.
A05:2021-Security MisconfigurationPerforms a TLS handshake and reports whether the certificate chain and hostname validate, and how much runway is left before it expires.
A02:2021-Cryptographic FailuresReports which TLS version the server negotiated. TLS 1.0 and 1.1 are deprecated and rejected by current browsers.
A02:2021-Cryptographic FailuresChecks that form actions don't submit data over plain HTTP when the page is HTTPS, which would expose credentials and form data.
A02:2021-Cryptographic FailuresChecks that pages with password inputs are served over HTTPS.
A02:2021-Cryptographic FailuresDetects forms that POST data to a different domain, which may indicate data exfiltration or misconfigured third-party integrations.
A04:2021-Insecure DesignChecks that the site is served over HTTPS. Content delivered over plain HTTP can be read and modified by anyone on the network path.
A02:2021-Cryptographic FailuresTests common redirect parameters with an external marker URL to find redirects that will send your users to any attacker-chosen site.
A01:2021-Broken Access ControlChecks the response body for error messages that indicate the domain points to an unclaimed third-party service (GitHub Pages, S3, Heroku, etc.), enabling subdomain takeover.
A05:2021-Security MisconfigurationChecks for a <link rel="canonical"> that tells search engines which URL is the definitive version of this page.
Checks that the canonical link, when present, points to the page's own URL (self-referencing) or a clearly intended alternative.
Checks that the page declares its character encoding (ideally UTF-8) early in the document, preventing garbled text and crawl issues.
Checks for multiple <title> or <meta name='description'> elements, which confuses search engines about which to use.
Checks that external links with target=_blank include rel="noopener" to prevent the linked page from accessing window.opener.
Checks that the page declares a favicon, which appears in browser tabs, bookmarks, and search results.
Checks that the page has exactly one H1 heading, establishing a clear topic for both users and search engines.
Checks that headings follow a logical hierarchy (h1→h2→h3) without skipping levels, which helps both SEO and accessibility.
Reports images without alt attributes, which hurts accessibility and prevents search engines from understanding image content.
Checks that <img> elements include explicit width and height attributes, preventing layout shift (CLS) and improving Core Web Vitals scores.
Checks that any JSON-LD structured data on the page is valid JSON and contains the required @type property.
Checks that the <html> element declares a language, helping search engines and screen readers process the content correctly.
Checks that links use descriptive anchor text instead of generic phrases like 'click here', which harms both SEO and accessibility.
Checks for a meta description within the recommended length range for search result snippets.
Checks whether internal links are accidentally marked nofollow, which wastes link equity and hurts internal page authority.
Checks for a noindex meta tag or X-Robots-Tag header that prevents search engines from indexing the page.
Checks for essential Open Graph meta tags (og:title, og:description, og:image) that control how links appear when shared on social media.
Checks that og:image includes width and height meta tags, which helps platforms render previews without loading the image first.
Checks for render-blocking JavaScript and CSS in the <head> that delay First Contentful Paint, hurting Core Web Vitals and search rankings.
Checks if robots.txt contains a blanket Disallow: / for all user agents, which prevents all search engine indexing.
Checks that robots.txt exists, is valid, and contains useful directives beyond just allowing everything.
Checks for a sitemap.xml file that helps search engines discover and prioritize pages on your site.
Checks that the page returns an appropriate 2xx status code and doesn't use soft redirects or error pages that return 200.
Checks for inline styles or CSS that make interactive elements too small for comfortable mobile tapping (< 44x44px).
Checks that the page has sufficient text content (>100 words) to be considered substantive by search engines.
Checks that the page has a <title> element within the recommended length range for search result display.
Checks for Twitter/X Card meta tags that control how the page appears when shared on Twitter/X.
Checks that the page URL is clean, descriptive, and free of excessive parameters or cryptic IDs that harm SEO.
Checks for a viewport meta tag, which is required for mobile-friendly rendering and affects mobile search rankings.
Checks whether the server sends an X-Robots-Tag header that blocks indexing (noindex) or following links (nofollow), which may be unintentional in production.
Checks whether the page uses question-style or clear topic headings that AI systems can identify and extract as direct answers to user queries.
Checks for authorship, organization, and publication date signals that AI systems use when deciding whether and how to cite content in generated answers.
Checks whether AI crawlers are given appropriate crawl-delay or rate limits in robots.txt to manage server load without blocking them entirely.
Checks whether robots.txt explicitly blocks major AI crawlers, which prevents your content from appearing in AI-generated answers.
Examines robots.txt for granular AI crawler directives — reports which AI crawlers are explicitly blocked or allowed, helping site owners make informed visibility decisions.
Checks that the page clearly identifies what entity (brand, person, organization) is behind the content, which AI systems use for attribution and trust signals.
Checks whether the page's main content is present in the initial HTML response, since AI crawlers and answer engines typically cannot execute JavaScript.
Checks for FAQPage or QAPage schema markup that helps AI systems identify and extract question-answer pairs from your content.
Checks for Last-Modified headers and dateModified schema properties that signal content currency to AI systems.
Checks for HowTo schema on pages that contain step-by-step instructions, which helps AI systems extract procedural knowledge.
Checks whether the site publishes an /llms.txt file that helps AI systems understand what content is available for extraction.
Checks for semantic HTML5 landmark elements (main, article, nav, header) that help AI systems identify and extract meaningful content regions.
Checks for application/ld+json script blocks containing structured data, and whether the JSON is valid.
Checks whether the page's first paragraph provides a clear, concise summary that AI systems can extract as a direct answer or featured snippet.
Checks that the HTML response includes Cache-Control, ETag or Last-Modified so browsers and CDNs can avoid re-downloading unchanged content.
Checks that the HTML document is served gzip- or brotli-compressed, which typically cuts transfer size by 60-80%.
Counts the page's DOM nodes and flags pages far past the ~800-node depth where style recalculation and reflow costs start to bite.
Checks @font-face rules for a font-display strategy so text renders immediately instead of waiting on slow font downloads.
Checks that image-heavy pages use loading="lazy" so off-screen images don't compete with the content the visitor actually sees first.
Flags pages serving several JPEG/PNG images with no WebP/AVIF anywhere — typically about twice the image bytes visitors must download.
Checks that image-heavy pages provide srcset variants so mobile visitors download mobile-sized images instead of desktop originals.
Checks the transferred size of the HTML document itself. Bloated HTML delays first paint and eats mobile data budgets.
Counts the HTTP redirects a visitor's browser follows before receiving the page. Each hop adds a full round trip before any content loads.
Counts stylesheets and synchronous scripts in the document head. Each one blocks the browser from painting anything until it downloads.
Checks that pages loading assets from third-party origins declare preconnect / dns-prefetch hints so the browser can warm those connections early.
Measures how long the server takes to deliver the HTML document. Slow servers push back every other improvement a visitor experiences.
Checks the page's initial HTML for a recognisable cookie-consent banner or consent-management-platform script.
Checks that the page links to a privacy policy somewhere in the document.
Runs the axe-core accessibility engine against the live, rendered page (including same-origin and cross-origin iframes) and reports WCAG rule violations.
Checks for a DMARC policy record at _dmarc.{domain}, which tells receiving mail servers what to do with mail that fails SPF/DKIM authentication.
Checks for a valid Sender Policy Framework (SPF) TXT record, which tells receiving mail servers which hosts are authorized to send email for this domain.
Checks whether the domain's delegation is DNSSEC-signed, via RDAP secureDNS.delegationSigned.
Checks how much time remains before the domain's registration expires, via RDAP.
Checks whether the domain has a registrar transfer-prohibited lock (EPP status) set, via RDAP.