SECURITY · SEO · AEO
Every check,one scanner.
47 scanners covering security, SEO, AEO, domain, email, performance and accessibility. Every issue ships with a fix prompt ready to paste into your AI.
Security Headers Scanner
Checks that your site sends key HTTP security headers like CSP, HSTS and X-Frame-Options.
View detail →SecurityInsecure Cookie Scanner
Detects cookies missing the Secure, HttpOnly or SameSite attributes that guard against theft and CSRF.
View detail →SecurityPermissive CORS Scanner
Checks whether your CORS policy reflects any origin with credentials, exposing your users' data.
View detail →SecuritySensitive File Exposure Scanner
Probes for exposed files like .env, .git, SSH keys or DB backups that leak secrets and code.
View detail →SecurityJavaScript Secret Scanner
Scans your browser JavaScript for leaked API keys and credentials like Stripe, AWS or Supabase.
View detail →SecurityTLS Certificate Scanner
Checks whether your site uses HTTPS and if its certificate is expired, expiring soon or uses old TLS.
View detail →SecurityHeader Info Disclosure Scanner
Detects headers like X-Powered-By or Server that reveal your tech stack and version to attackers.
View detail →Securitysecurity.txt Checker
Checks whether you publish a security.txt file (RFC 9116) so researchers can report vulnerabilities.
View detail →SecurityDirectory Listing Scanner
Checks whether folders like /uploads or /backup expose a browsable listing of all their files.
View detail →SecurityMixed Content Scanner
Detects resources loaded over HTTP on an HTTPS page that travel unencrypted and break the padlock.
View detail →SecurityHTTPS Redirect Checker
Checks that the HTTP version of your site properly redirects to HTTPS instead of serving unencrypted.
View detail →SecurityWeak CSP Scanner
Detects unsafe directives like 'unsafe-inline' or 'unsafe-eval' that weaken your CSP's XSS protection.
View detail →Securityrobots.txt Exposure Scanner
Detects sensitive paths (admin, backups, .git) listed in robots.txt that signal them to attackers.
View detail →SecurityWeak HSTS Scanner
Detects an HSTS header with a low max-age or missing includeSubDomains that leaves downgrade gaps.
View detail →SecurityWordPress Exposure Scanner
Detects exposed WordPress version, accessible readme.html and user enumeration via the wp-json API.
View detail →SecurityHTTP Methods Scanner
Checks whether the server advertises risky HTTP methods like TRACE, PUT or DELETE it shouldn't.
View detail →SecurityOrigin Isolation Headers Scanner
Checks for missing COOP and CORP headers that isolate your site against cross-origin attacks.
View detail →SecurityExposed Endpoint Scanner
Probes for debug panels and endpoints (Actuator, Telescope, Ignition, phpMyAdmin) exposed in production.
View detail →SecurityGraphQL Introspection Scanner
Checks whether your GraphQL endpoint exposes its full API schema via enabled introspection.
View detail →SecurityInternal Reference Scanner
Detects links to localhost or internal IPs in the HTML, dev leftovers that leak your infrastructure.
View detail →SecurityInsecure Form Scanner
Detects password forms served over HTTP or submitting credentials to an unencrypted URL.
View detail →SecurityHTML Comment Secret Scanner
Scans HTML comments for forgotten keys, passwords or tokens that anyone viewing the source can read.
View detail →SecurityToken Storage Scanner
Detects whether your JavaScript stores tokens in localStorage/sessionStorage, vulnerable to XSS theft.
View detail →SecurityWeak Referrer-Policy Scanner
Detects a permissive Referrer-Policy that leaks your site's full URL to external destinations.
View detail →SecuritySensitive Cache Scanner
Detects responses with a session cookie marked cacheable that a shared CDN could serve to another user.
View detail →SecuritySubresource Integrity Scanner
Detects scripts and styles loaded from external CDNs without the integrity attribute that verifies them.
View detail →SecurityOutdated Library Scanner
Detects vulnerable or end-of-life versions of jQuery, AngularJS and Bootstrap with known XSS CVEs.
View detail →SecuritySource Map Exposure Scanner
Checks whether your source maps (.map) are accessible and let anyone rebuild your original source code.
View detail →EmailEmail Authentication Scanner
Checks the domain's SPF, DKIM, DMARC, MX, BIMI and MTA-STS records to prevent email spoofing.
View detail →DomainDomain Health Scanner
Checks your domain's CAA and DNSSEC records and its expiry date to keep it protected.
View detail →PerformanceCore Web Vitals Scanner
Measures mobile performance via PageSpeed (LCP, CLS, TBT) and flags metrics in the poor range.
View detail →AccessibilityWeb Accessibility Scanner
Checks language, image alt text, form labels, viewport and duplicate IDs against WCAG rules.
View detail →SecurityExposed Backup Scanner
Probes for downloadable site archives and SQL dumps that expose your source code and data.
View detail →SecurityExposed Log Scanner
Probes for log files accessible over HTTP that leak paths, error traces and internal data.
View detail →SecurityDependency Manifest Scanner
Detects accessible package.json or composer.json files that reveal your exact dependencies and versions.
View detail →SEOSEO Meta Tag Scanner
Checks your page's title, meta description and canonical tag to improve search ranking.
View detail →SEOSEO Heading Scanner
Checks that your page has exactly one <h1> that clearly defines its main topic.
View detail →SEOOpen Graph Scanner
Checks Open Graph tags (og:title, description, image) for a rich preview when your site is shared.
View detail →SEORobots & Sitemap Scanner
Checks robots.txt, sitemap.xml and whether the homepage is set to noindex, key for Google indexing.
View detail →SEOBroken Link Scanner
Crawls your page's internal links and flags those returning 404, 410 or 5xx errors.
View detail →AEOllms.txt Checker
Checks whether you publish an llms.txt file to guide AI assistants toward your key content.
View detail →AEOStructured Data Scanner
Checks whether your page has schema.org structured data (JSON-LD) for rich results and AI answers.
View detail →AEONo-JavaScript Content Scanner
Detects whether your site is a near-empty SPA without JS that AI crawlers can't index or cite.
View detail →AEOAI Visibility Scanner
Asks an AI model whether it recognizes your brand, revealing if you show up in AI answers.
View detail →AEOAI Crawler Access Scanner
Checks whether your robots.txt blocks AI bots like GPTBot or ClaudeBot, limiting your AI visibility.
View detail →SecurityThreat Reputation Scanner
Queries Google Safe Browsing to check whether your site is flagged as malware or phishing.
View detail →ComplianceCompliance & Cookies Scanner
Checks whether you link a privacy policy and handle cookie consent (GDPR).
View detail →Run them all in 30 seconds
Paste your URL and get a complete report with a fix prompt for every issue.
Scan my site free