Every finding ranked
by risk level
Performance metrics
at a glance
// scan_modules
Nine inspection layers, one report.
Every scan covers 30+ checks across 9 security and quality domains, completed in under 60 seconds.
Security headers
HSTS, CSP, X-Frame, X-Content-Type, Referrer-Policy, Permissions-Policy, server disclosure, mixed content.
SSL / TLS
Certificate validity, expiry, issuer, self-signed detection, A+ grading, HTTPS redirect hygiene.
SEO
Title, meta description, headings, canonical, Open Graph, Twitter cards, JSON-LD, robots.txt, sitemap.
Performance
TTFB, response time, payload size, compression (gzip/br), caching headers, external script count.
Accessibility
Viewport, language attribute, alt text coverage, semantic structure, favicon, manifest, keyboard traps.
Email DNS
SPF, DMARC, MX records — email spoofing and phishing attack surface analysis.
Domain & WHOIS
Registrar, registrant, country, domain age, expiry date, nameservers via RDAP/WHOIS.
Hosting & IP
Resolved IP, ISP, ASN, city/country geolocation, reverse DNS, CDN detection.
AI briefing
GPT-4o executive summary: overall posture, top 3 priorities to fix, what's already done well.
From URL to full report in 3 steps
Enter any URL
Website, web app, mobile app URL, or IP address. We resolve and normalise it automatically.
60-second deep scan
30+ checks run in parallel: SSL, headers, SEO, DNS, WHOIS, tech stack, AI briefing.
Receive your report
Score, grade, ranked findings, and AI summary online instantly. Full PDF via email.
// ai_engine
An analyst that explains, prioritizes, and recommends.
Every scan is interpreted by an AI engine that turns raw findings into an executive briefing, a prioritized action list, and concrete remediation guidance — written in plain language.
- Risk-ranked findings with business impact in plain language
- Executive summary ready to share with non-technical stakeholders
- Concrete remediation steps engineers can ship immediately
- Identifies what's already done well — not just what's broken
> GET https://example.com 200 OK 142ms
✓ TLS 1.3 + HSTS enforced
✗ missing content-security-policy
✗ server header exposes: nginx/1.18.0
✓ x-content-type-options: nosniff
✗ /sitemap.xml not found
✓ SPF record found
✗ no DMARC policy
WHOIS: GoDaddy · age 6.2 yrs · expires 2026-03
Host: Cloudflare · AS13335 · United States
[ssl] grade: A · valid 284 days
[scores] security: 58 seo: 85 perf: 73
[ai] Posture is moderate. The most urgent
gap is the missing CSP header.Ready to inspect any link?
Free, instant, no account needed. Paste any URL and get your full report.