SCANNERS ONLINE / 214 CHECKS PER PASS / MEDIAN RUNTIME 38.4s LAST INDEX SYNC 00:04:12 AGO
Free scan · no card · no install

Security, SEO & AI visibility,
scanned in one pass.

Findings ranked by what to fix first — 214 checks across six layers — security, SEO, AI visibility, performance, uptime and compliance — with a paste-ready fix for every single finding.

https://
FULL REPORT IN ~40s READ-ONLY PROBES ◆ AVG. 4.1 CRITICALS PER FIRST SCAN
11,240sites scanned
38.4smedian runtime
6audit pillars
214checks per pass
sitehealthscan.com · run/8f2c41 · your-app.dev SCANNING
4
criticals found
SURFACE MAP · 41 ROUTES · 12 ORIGINS
82
SEC
67
SEO
45
AEO
91
PERF
CSP header policyRLS policy gaps.env leakage in bundle CORS wildcard originsJWT expiry + algorithmCore Web Vitals robots.txt AI crawler rulesllms.txt presenceschema.org coverage TLS chain + expiryDNSSECopen redirects SQLi probe surfacecookie consent signalsWCAG contrastCSP header policyRLS policy gaps.env leakage in bundle CORS wildcard originsJWT expiry + algorithmCore Web Vitals robots.txt AI crawler rulesllms.txt presenceschema.org coverage TLS chain + expiryDNSSECopen redirects SQLi probe surfacecookie consent signalsWCAG contrast
01coverage.map 6 PILLARS · 214 CHECKS

Six layers. One pass.

Every pillar runs against your live site in parallel. Nothing installed, nothing written, nothing submitted — read-only probes of what the public internet can already reach.

P01 / SECURITY82/100

Security

Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.

112 CHECKS3 open
P02 / SEO67/100

Search

Crawlability, sitemap and canonical integrity, metadata completeness, internal link graph, index eligibility per route.

68 CHECKS11 open
P03 / AEO45/100

AI visibility

Whether answer engines can parse, trust and cite you. Structured data coverage, llms.txt, crawler permissions, claim extractability.

46 CHECKS19 open
P04 / PERF91/100

Performance

Core Web Vitals under throttled conditions, bundle weight, render-blocking chains, image and font delivery.

34 CHECKS1 open
P05 / WATCH24/7

Monitoring

Sixty-second uptime probes, certificate and domain expiry runway, live attack telemetry, score-drift alerts.

CONTINUOUSarmed
P06 / LEGAL78/100

Compliance

Cookie and consent signalling, privacy surface, WCAG contrast and semantics, regional disclosure requirements.

28 CHECKS6 open
02findings.ranked SORTED BY BLAST RADIUS

Ranked by what actually breaks trust.

Not an alphabetised wall of warnings. Findings are ordered by what a real attacker or a real crawler reaches first — and each one carries a fix you can paste straight into your coding agent.

RUN 8F2C41 YOUR-APP.DEV 40 FINDINGS · 4 CRITICAL
01
critical
Supabase service-role key reachable in client bundle /_app/immutable/chunks/
SECURITY
Get fix prompt →
02
critical
Row-level security disabled on public.profiles — full table readable
SECURITY
Get fix prompt →
03
critical
Wildcard CORS Access-Control-Allow-Origin: * on authenticated routes
SECURITY
Get fix prompt →
04
warning
No llms.txt — answer engines have no citation policy to follow
AEO
Get fix prompt →
05
warning
Structured data absent on 34 of 41 indexable routes
AEO
Get fix prompt →
06
warning
Content-Security-Policy missing frame-ancestors directive
SECURITY
Get fix prompt →
07
passed
TLS chain valid, 74 days of runway remaining
SECURITY
—
36 further findings — including 1 remaining critical — are held behind the free tier. Unlock the full report →
03pipeline.seq PASTE → SCAN → PATCH

Three steps, and one of them is pasting a URL.

STEP 01
◦

Point it at the site

Production, staging, or the thing you built on a Sunday. Optionally connect GitHub and your database for a deeper pass at the code behind it.

STEP 02
◈

214 checks run in parallel

Six pillars execute at once against the live surface. Median wall-clock time is under forty seconds, including a full crawl and a throttled vitals run.

STEP 03
◆

Hand the fixes to your agent

Every finding compiles into a prompt with file paths and context. Paste it into Claude Code, Cursor or Codex — or wire SiteHealthScan.com in over MCP and let it dispatch directly.

04stack.replace EIGHT TABS → ONE

What you're currently doing in eight tabs.

Most teams stitch this together from a header checker, a Lighthouse run, an uptime pinger and a lot of hoping. Here's the same coverage in one pass.

Capability SiteHealthScan.com Header checkers Lighthouse Uptime pingers
Security headers & CSPsurface config■ full■ full□ none□ none
Exposed secrets in bundleclient-side leakage■ full□ none□ none□ none
Database policy gapsRLS & row exposure■ full□ none□ none□ none
Core Web Vitalsthrottled field run■ full□ none■ full□ none
Technical SEO crawlsitemap, canonical, meta■ full□ none▪ partial□ none
AI answer-engine visibilitycitation eligibility■ full□ none□ none□ none
Continuous monitoringuptime & score drift■ full□ none□ none▪ uptime only
Paste-ready remediationagent-executable■ full□ none□ none□ none
MCP + REST accesspipe into your agent■ full□ none▪ CLI only▪ webhook
05telemetry.live HISTORY IS KEPT

Watch it get better.

Every scan is retained and diffed. When a deploy quietly regresses your score, you hear about it from us — not from a customer.

88 ▲ 31 pts since first scan OVERALL HEALTH · 90 DAYS
DAY 01 · 57DAY 30DAY 60TODAY · 88
zsh — sitehealthscan mcp
$ claude mcp add sitehealthscan
✓ connected · 26 tools exposed
> scan your-app.dev --fix
running 214 checks ······· 38.4s
✗ 4 critical · 12 warning
patching 3 files ········· done
$
06plans.json CANCEL ANY TIME

The scan is free. The fixes aren't.

Run as many free scans as you like — you'll always see your score and your critical count. Paid plans open the full findings, the remediation prompts and continuous monitoring.

Recon

See where you stand. No card, no expiry.

$0
FOREVER
  • Unlimited scans on <b>1 site</b>
  • All six pillar scores
  • Critical count and severity split
  • Top <b>4 findings</b> in full
Start scanning
◆ most chosen

Operator

The full report, plus a fix for every line of it.

$29/mo
PER SEAT · BILLED MONTHLY
  • <b>Every finding</b>, fully detailed
  • Paste-ready <b>fix prompts</b> per issue
  • Up to <b>10 sites</b>, scheduled re-scans
  • Daily monitoring with drift alerts
  • PDF and Markdown exports
Unlock the report →

Command

For agencies shipping other people's sites.

$99/mo
PER SEAT · BILLED MONTHLY
  • Everything in Operator
  • <b>Unlimited sites</b> and API access
  • <b>MCP server</b> — agents dispatch fixes directly
  • GitHub and database connected scans
  • White-label client reports
Talk to us
07questions.md THE HONEST ANSWERS

Before you paste the URL.

Q1Is it safe to run against a live production site?+
Yes. Every check is a read-only probe of something already publicly reachable. Nothing is written, submitted, mutated or stored on your side. The scan looks like ordinary traffic — a crawler and a handful of header requests.
Q2What is AEO, and why does it have its own pillar?+
Answer Engine Optimisation. People increasingly ask ChatGPT, Claude or Perplexity what tool to use rather than typing into a search box. AEO checks whether those systems can reach your content, parse a clear claim out of it, and cite you. It fails differently from SEO, so it gets scored separately.
Q3Do I need to install anything or change my code?+
No. Paste a URL and the scan runs against the live surface. Connecting your repository or database is optional and only widens what we can see — it is never required for a score.
Q4What exactly does a "fix prompt" contain?+
The finding, the affected file paths or routes, the relevant framework context, and the change to make — written to be pasted directly into a coding agent. On the Command plan, SiteHealthScan.com connects over MCP and applies them itself rather than handing you text.
Q5Will a bad score be shown publicly?+
Never by default. Reports are private to your account. There is an opt-in public leaderboard for builders who want to show a clean score — it is off unless you switch it on, and it can be switched back off at any time.

Find it before
somebody else does.

Forty seconds, no account, and you'll know your critical count.

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.