Security
Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.
Findings ranked by what to fix first — 214 checks across six layers — security, SEO, AI visibility, performance, uptime and compliance — with a paste-ready fix for every single finding.
Every pillar runs against your live site in parallel. Nothing installed, nothing written, nothing submitted — read-only probes of what the public internet can already reach.
Response headers, exposed keys and secrets, row-level-security gaps, CORS posture, injection surface, auth token hygiene.
Crawlability, sitemap and canonical integrity, metadata completeness, internal link graph, index eligibility per route.
Whether answer engines can parse, trust and cite you. Structured data coverage, llms.txt, crawler permissions, claim extractability.
Core Web Vitals under throttled conditions, bundle weight, render-blocking chains, image and font delivery.
Sixty-second uptime probes, certificate and domain expiry runway, live attack telemetry, score-drift alerts.
Cookie and consent signalling, privacy surface, WCAG contrast and semantics, regional disclosure requirements.
Not an alphabetised wall of warnings. Findings are ordered by what a real attacker or a real crawler reaches first — and each one carries a fix you can paste straight into your coding agent.
/_app/immutable/chunks/public.profiles — full table readableAccess-Control-Allow-Origin: * on authenticated routesllms.txt — answer engines have no citation policy to followProduction, staging, or the thing you built on a Sunday. Optionally connect GitHub and your database for a deeper pass at the code behind it.
Six pillars execute at once against the live surface. Median wall-clock time is under forty seconds, including a full crawl and a throttled vitals run.
Every finding compiles into a prompt with file paths and context. Paste it into Claude Code, Cursor or Codex — or wire SiteHealthScan.com in over MCP and let it dispatch directly.
Most teams stitch this together from a header checker, a Lighthouse run, an uptime pinger and a lot of hoping. Here's the same coverage in one pass.
| Capability | SiteHealthScan.com | Header checkers | Lighthouse | Uptime pingers |
|---|---|---|---|---|
| Security headers & CSPsurface config | ■ full | ■ full | □ none | □ none |
| Exposed secrets in bundleclient-side leakage | ■ full | □ none | □ none | □ none |
| Database policy gapsRLS & row exposure | ■ full | □ none | □ none | □ none |
| Core Web Vitalsthrottled field run | ■ full | □ none | ■ full | □ none |
| Technical SEO crawlsitemap, canonical, meta | ■ full | □ none | ▪ partial | □ none |
| AI answer-engine visibilitycitation eligibility | ■ full | □ none | □ none | □ none |
| Continuous monitoringuptime & score drift | ■ full | □ none | □ none | ▪ uptime only |
| Paste-ready remediationagent-executable | ■ full | □ none | □ none | □ none |
| MCP + REST accesspipe into your agent | ■ full | □ none | ▪ CLI only | ▪ webhook |
Every scan is retained and diffed. When a deploy quietly regresses your score, you hear about it from us — not from a customer.
Run as many free scans as you like — you'll always see your score and your critical count. Paid plans open the full findings, the remediation prompts and continuous monitoring.
See where you stand. No card, no expiry.
The full report, plus a fix for every line of it.
For agencies shipping other people's sites.
Forty seconds, no account, and you'll know your critical count.