SECURITY · SEO · AEO

Every check,one scanner.

47 scanners covering security, SEO, AEO, domain, email, performance and accessibility. Every issue ships with a fix prompt ready to paste into your AI.

Security

Security Headers Scanner

Checks that your site sends key HTTP security headers like CSP, HSTS and X-Frame-Options.

View detail →
Security

Insecure Cookie Scanner

Detects cookies missing the Secure, HttpOnly or SameSite attributes that guard against theft and CSRF.

View detail →
Security

Permissive CORS Scanner

Checks whether your CORS policy reflects any origin with credentials, exposing your users' data.

View detail →
Security

Sensitive File Exposure Scanner

Probes for exposed files like .env, .git, SSH keys or DB backups that leak secrets and code.

View detail →
Security

JavaScript Secret Scanner

Scans your browser JavaScript for leaked API keys and credentials like Stripe, AWS or Supabase.

View detail →
Security

TLS Certificate Scanner

Checks whether your site uses HTTPS and if its certificate is expired, expiring soon or uses old TLS.

View detail →
Security

Header Info Disclosure Scanner

Detects headers like X-Powered-By or Server that reveal your tech stack and version to attackers.

View detail →
Security

security.txt Checker

Checks whether you publish a security.txt file (RFC 9116) so researchers can report vulnerabilities.

View detail →
Security

Directory Listing Scanner

Checks whether folders like /uploads or /backup expose a browsable listing of all their files.

View detail →
Security

Mixed Content Scanner

Detects resources loaded over HTTP on an HTTPS page that travel unencrypted and break the padlock.

View detail →
Security

HTTPS Redirect Checker

Checks that the HTTP version of your site properly redirects to HTTPS instead of serving unencrypted.

View detail →
Security

Weak CSP Scanner

Detects unsafe directives like 'unsafe-inline' or 'unsafe-eval' that weaken your CSP's XSS protection.

View detail →
Security

robots.txt Exposure Scanner

Detects sensitive paths (admin, backups, .git) listed in robots.txt that signal them to attackers.

View detail →
Security

Weak HSTS Scanner

Detects an HSTS header with a low max-age or missing includeSubDomains that leaves downgrade gaps.

View detail →
Security

WordPress Exposure Scanner

Detects exposed WordPress version, accessible readme.html and user enumeration via the wp-json API.

View detail →
Security

HTTP Methods Scanner

Checks whether the server advertises risky HTTP methods like TRACE, PUT or DELETE it shouldn't.

View detail →
Security

Origin Isolation Headers Scanner

Checks for missing COOP and CORP headers that isolate your site against cross-origin attacks.

View detail →
Security

Exposed Endpoint Scanner

Probes for debug panels and endpoints (Actuator, Telescope, Ignition, phpMyAdmin) exposed in production.

View detail →
Security

GraphQL Introspection Scanner

Checks whether your GraphQL endpoint exposes its full API schema via enabled introspection.

View detail →
Security

Internal Reference Scanner

Detects links to localhost or internal IPs in the HTML, dev leftovers that leak your infrastructure.

View detail →
Security

Insecure Form Scanner

Detects password forms served over HTTP or submitting credentials to an unencrypted URL.

View detail →
Security

HTML Comment Secret Scanner

Scans HTML comments for forgotten keys, passwords or tokens that anyone viewing the source can read.

View detail →
Security

Token Storage Scanner

Detects whether your JavaScript stores tokens in localStorage/sessionStorage, vulnerable to XSS theft.

View detail →
Security

Weak Referrer-Policy Scanner

Detects a permissive Referrer-Policy that leaks your site's full URL to external destinations.

View detail →
Security

Sensitive Cache Scanner

Detects responses with a session cookie marked cacheable that a shared CDN could serve to another user.

View detail →
Security

Subresource Integrity Scanner

Detects scripts and styles loaded from external CDNs without the integrity attribute that verifies them.

View detail →
Security

Outdated Library Scanner

Detects vulnerable or end-of-life versions of jQuery, AngularJS and Bootstrap with known XSS CVEs.

View detail →
Security

Source Map Exposure Scanner

Checks whether your source maps (.map) are accessible and let anyone rebuild your original source code.

View detail →
Email

Email Authentication Scanner

Checks the domain's SPF, DKIM, DMARC, MX, BIMI and MTA-STS records to prevent email spoofing.

View detail →
Domain

Domain Health Scanner

Checks your domain's CAA and DNSSEC records and its expiry date to keep it protected.

View detail →
Performance

Core Web Vitals Scanner

Measures mobile performance via PageSpeed (LCP, CLS, TBT) and flags metrics in the poor range.

View detail →
Accessibility

Web Accessibility Scanner

Checks language, image alt text, form labels, viewport and duplicate IDs against WCAG rules.

View detail →
Security

Exposed Backup Scanner

Probes for downloadable site archives and SQL dumps that expose your source code and data.

View detail →
Security

Exposed Log Scanner

Probes for log files accessible over HTTP that leak paths, error traces and internal data.

View detail →
Security

Dependency Manifest Scanner

Detects accessible package.json or composer.json files that reveal your exact dependencies and versions.

View detail →
SEO

SEO Meta Tag Scanner

Checks your page's title, meta description and canonical tag to improve search ranking.

View detail →
SEO

SEO Heading Scanner

Checks that your page has exactly one <h1> that clearly defines its main topic.

View detail →
SEO

Open Graph Scanner

Checks Open Graph tags (og:title, description, image) for a rich preview when your site is shared.

View detail →
SEO

Robots & Sitemap Scanner

Checks robots.txt, sitemap.xml and whether the homepage is set to noindex, key for Google indexing.

View detail →
SEO

Broken Link Scanner

Crawls your page's internal links and flags those returning 404, 410 or 5xx errors.

View detail →
AEO

llms.txt Checker

Checks whether you publish an llms.txt file to guide AI assistants toward your key content.

View detail →
AEO

Structured Data Scanner

Checks whether your page has schema.org structured data (JSON-LD) for rich results and AI answers.

View detail →
AEO

No-JavaScript Content Scanner

Detects whether your site is a near-empty SPA without JS that AI crawlers can't index or cite.

View detail →
AEO

AI Visibility Scanner

Asks an AI model whether it recognizes your brand, revealing if you show up in AI answers.

View detail →
AEO

AI Crawler Access Scanner

Checks whether your robots.txt blocks AI bots like GPTBot or ClaudeBot, limiting your AI visibility.

View detail →
Security

Threat Reputation Scanner

Queries Google Safe Browsing to check whether your site is flagged as malware or phishing.

View detail →
Compliance

Compliance & Cookies Scanner

Checks whether you link a privacy policy and handle cookie consent (GDPR).

View detail →

Run them all in 30 seconds

Paste your URL and get a complete report with a fix prompt for every issue.

Scan my site free