Your website sucks.

Find out why — free in 60 seconds.

Free frontend audit for everyone. Subscribe for deep backend analysis.

Free • No account required • Results in 60 seconds

106 checks
70 free
5 categories
2 languages
SEO Intelligence
106 checks

What we analyze

Every check runs automatically — add a URL and we handle the rest.

Database Optimization Pro

Analyzes database tables for fragmentation and auto-increment limits.

Database Performance Pro

Analyzes MySQL configuration, slow query log, buffer sizes, and connection usage.

Server-Side Compression Pro

Verifies that the server delivers compressed responses (gzip/deflate/brotli).

PHP Memory & Execution Limits Pro

Validates PHP memory_limit, max_execution_time, and upload size configuration.

Object Cache Pro

Checks for Redis or Memcached object caching to reduce database load.

OPcache Configuration Pro

Analyzes PHP OPcache status and configuration for optimal performance.

Server Resources Pro

Monitors disk space, memory usage, CPU load, and inode consumption on the server.

Caching Headers

Verifies Cache-Control, ETag, Last-Modified, and Expires headers for efficient browser caching.

Carbon Footprint

Estimates the CO2 emissions per page view based on page weight and resource count, using Green Web Foundation methodology.

Core Web Vitals

Measures real-user experience metrics: LCP (loading), CLS (visual stability), and INP (interactivity) using headless Chrome.

CSS @import

Detects CSS @import rules that create additional render-blocking round trips.

DOM Complexity

Counts DOM elements to detect overly complex pages that slow down rendering.

Font Optimization

Checks font loading strategy, number of font families, and font-display usage.

HTTP/2 Protocol

Checks if the server supports HTTP/2 for faster page loading.

HTTP/3 Support

This site does not advertise HTTP/3 (QUIC) support.

Image Optimization

Checks for modern formats (WebP/AVIF), explicit dimensions, responsive images, and optimization.

Critical CSS

Checks for inline critical CSS and render-blocking stylesheet optimization.

Image Lazy Loading

Checks that offscreen images use loading="lazy" and above-the-fold images do not, to optimize loading performance.

Page Weight

Measures the total transfer size of the HTML document.

Resource Hints

Checks for dns-prefetch, preconnect, preload, and prefetch link hints to optimize resource loading.

Resource Optimization

Checks compression, render-blocking resources, lazy loading, and page size.

Third-Party Scripts

Analyzes external scripts loaded on the page and their impact on performance.

Time to First Byte (TTFB)

Measures server response time — the delay before the first byte of the page is received.

Sensitive File Exposure Pro

Probes for publicly accessible sensitive files and directories (.git, .env, backups, config files).

Admin Panel Access Pro

Checks if admin panels and database tools are publicly accessible without restrictions.

Known Vulnerabilities Pro

Cross-references your CMS version, plugins, and themes against known CVE vulnerabilities from NVD, WPScan, and Packagist.

CMS-Specific Security Pro

CMS-specific security and performance checks tailored to your platform.

Composer Dependencies Pro

Analyzes composer.lock for outdated or vulnerable packages.

Database Security Pro

Checks database user privileges, MySQL/MariaDB version, and remote access settings.

Debug Mode Detection Pro

Detects if debug/development modes are enabled in production across CMS and frameworks.

Default Credentials & Secrets Pro

Detects default database usernames, table prefixes, admin accounts, and security keys.

Directory Listing Pro

Checks if directory listing (index of files) is enabled on public directories.

Environment & Sensitive Files Pro

Checks for exposed .env files, database backups, debug pages, and debug mode.

CMS Core File Integrity Pro

Compares CMS core file checksums against official versions to detect unauthorized modifications.

File Permissions Pro

Checks chmod permissions on critical configuration files and directories.

HTTP Redirect Configuration Pro

Validates HTTP to HTTPS redirect and www/non-www consistency.

Exposed Service Ports Pro

Scans for database and cache service ports accessible on localhost.

PHP Configuration Pro

Audits PHP version, dangerous INI directives, extensions, and OPcache status.

PHP Extensions Pro

Checks for dangerous extensions loaded in production and missing recommended extensions.

PHP Version End-of-Life Pro

Checks if the PHP version still receives security patches.

Server Configuration Pro

Analyzes .htaccess, server headers, and directory listing settings.

Session Security Pro

Checks session cookie configuration: Secure, HttpOnly, SameSite, and strict mode.

SSL/TLS Certificate Pro

Validates expiration, trust chain, and TLS protocol version (1.2 minimum).

Temporary Directory Security Pro

Audits permissions on /tmp and PHP session storage directories.

Web Server Fingerprinting Pro

Checks if the server exposes its software version in HTTP headers.

WordPress REST API Exposure Pro

Checks if the WordPress REST API exposes sensitive data like user listings.

XML-RPC Access Pro

Checks if WordPress XML-RPC endpoint is publicly accessible.

Cookie Security

Verifies Secure, HttpOnly, and SameSite attributes on cookies.

CORS Configuration

Cross-Origin Resource Sharing headers are misconfigured.

Content Security Policy Strictness

Your Content Security Policy is missing or contains weak directives that reduce its effectiveness.

Email Address Exposure

Detects email addresses displayed in plain text on the page.

Exposed Sensitive Files

Checks if sensitive files (.env, .git, backups, debug logs) are publicly accessible.

HSTS Preload Readiness

Your HSTS header is missing or not fully configured for preload submission.

HTTP Security Headers

Verifies CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.

Mixed Content

Detects HTTP resources loaded on an HTTPS page.

Redirect Chain

Checks for excessive HTTP redirections that slow down page loading.

Security.txt

No security.txt file found at /.well-known/security.txt.

Source Map Exposure

Checks whether JavaScript source maps (.map files) are publicly accessible, which exposes your original source code.

SSL/TLS Certificate

Validates expiration, trust chain, and TLS protocol version (1.2 minimum).

Subresource Integrity (SRI)

Checks whether external scripts and stylesheets use the integrity attribute to prevent tampering.

Author Attribution

No or insufficient author attribution detected. Author bios and bylines are key E-E-A-T signals.

Breadcrumb Structured Data

Breadcrumb navigation lacks structured data markup.

Broken Internal Links

Tests internal links for 404 and server errors.

Canonical URL Validation

Validates that the canonical URL is correctly configured: no duplicates, absolute URL, correct protocol, and consistent domain.

Citation Quality

Citation quality is weak. Linking to authoritative sources demonstrates expertise and authoritativeness.

Contact Information

Missing or insufficient contact information. Visible contact details are essential for trustworthiness.

Content Quality

Evaluates page word count and text-to-HTML ratio to detect thin or low-quality content.

Professional Credentials

No professional credentials or expertise signals found. Displaying qualifications builds E-E-A-T.

Hreflang Tags

Validates hreflang tags for multilingual/multi-region SEO.

Internal Linking

Analyzes the number of internal links and anchor text quality to assess site navigation and SEO link equity.

JavaScript Rendering Dependency

Compares server-rendered HTML with JS-rendered HTML to detect content that is only visible after JavaScript execution, which impacts SEO crawlability.

Open Graph & Social Meta

Checks Open Graph (og:) and Twitter Card meta tags for social media sharing.

Original Research & Data

No original research or first-hand data signals found. Original content is a key Experience signal.

Pagination SEO

Paginated content is missing rel="next"/"prev" link tags.

Privacy Policy & Compliance

Missing privacy policy or compliance signals. Privacy compliance is essential for trustworthiness.

Robots.txt

Checks for a valid robots.txt file with sitemap reference.

Structured Data Validation

Structured data schemas have missing or invalid required properties.

Technical SEO

Checks title tag, meta description, headings, canonical URL, and robots directives.

XML Sitemap

Validates the presence and format of an XML sitemap.

Structured Data

Detects JSON-LD, Microdata, or RDFa structured data (Schema.org).

Trust Signals

Insufficient trust signals found. Trust indicators like terms of service, reviews, and date information improve E-E-A-T.

Accessibility

Checks alt attributes, form labels, viewport meta, skip links, and heading hierarchy.

Accessibility Statement

No accessibility statement page found on this site.

ARIA & Landmarks

Validates ARIA roles, landmarks, and accessible interactive elements.

Visual Accessibility

Checks for small fonts, low contrast patterns, and zoom restrictions.

Form Accessibility

Checks that form inputs have associated labels (via <label>, aria-label, or aria-labelledby) and proper autocomplete attributes.

Keyboard Navigation

Checks for keyboard accessibility issues: negative tabindex on interactive elements and removed focus outlines.

Color Contrast (WCAG)

Measures actual foreground/background color contrast ratios using computed styles. WCAG 2.1 AA requires 4.5:1 for normal text and 3:1 for large text.

Reduced Motion Support

Animations detected but no prefers-reduced-motion media query found.

Touch Target Size

Checks interactive elements meet the WCAG 2.2 minimum target size of 24×24 CSS pixels for mobile usability.

Video Captions

Some videos are missing captions or subtitles.

Plugin & Update Health Pro

Checks for inactive plugins, outdated components, and excessive plugin count.

Cron Job Health Pro

Checks WordPress WP-Cron configuration, overdue scheduled tasks, and last execution time.

Error Handling Configuration Pro

Validates PHP error reporting, logging configuration, and error frequency in logs.

Error Log Analysis Pro

Analyzes PHP error logs for fatal errors, recurring warnings, and deprecations.

Email Authentication Pro

Checks DNS records for SPF, DKIM, and DMARC email authentication to prevent spoofing and improve deliverability.

Browser Console Errors

Detects JavaScript errors logged to the browser console during page load using headless Chrome.

Custom Error Pages

Verifies that 404 error pages return proper status codes and custom designs.

Deprecated HTML

Detects obsolete HTML tags and attributes that should be replaced with modern CSS.

Favicon

Checks for the presence of a favicon (browser tab icon).

Legal Compliance

Checks for essential legal pages and cookie consent mechanisms required by GDPR, ePrivacy Directive, and other regulations.

Responsive Design

Validates viewport configuration and responsive design indicators.

Semantic HTML Structure

Checks for HTML5 landmark elements (header, nav, main, footer, article, section) to ensure a well-structured, accessible document.

Service Worker

No service worker detected on this site.

Web App Manifest

Web app manifest is missing or incomplete.

How it works

Three steps to a better website

No setup, no account required. Just paste your URL and get actionable insights in under a minute.

Step 1

Enter your URL

Paste your website address and hit analyze. We handle the rest — no sign-up, no configuration.

Step 2

We run 70 checks

Our engine audits performance, security, SEO, accessibility and best practices in real time.

Step 3

Get your report

Every issue comes with a severity level, business impact explanation, and step-by-step remediation guide.

Go deeper

Unlock backend analysis

Install our read-only PHP probe for 36 additional server-side checks — database, PHP config, file permissions, and more.

Backend Audit

How the backend probe works

A persistent, read-only PHP file that continuously monitors your server configuration — secured by API key.

Your Server

yoursite.com

public_html/
index.php
wp-config.php
.htaccess
wmss-probe.php

PHP

8.3.2

MySQL

8.0.36

OPcache

ON

Perms

644

AES-256

WMSS Platform

Analysis engine

display_errors = On
Critical
slow_query_log = OFF
Major
File permissions OK
Passed

Five steps, zero risk

1

Download

We generate a unique single-file PHP probe secured by a dedicated API key.

2

Upload via FTP

Drop it at your website root — just like uploading any file.

3

Read-only scan

The probe reads PHP config, database settings, and file permissions. Nothing is modified.

4

Encrypted transfer

Results are encrypted with AES-256-GCM and sent over HTTPS to our servers.

5

Continuous monitoring

The probe stays on your server for ongoing backend audits. Remove it anytime from your dashboard.

Read-only — guaranteed

The probe never writes, modifies, or deletes any file or database record on your server.

End-to-end encrypted

All data is encrypted with AES-256-GCM before leaving your server. We use HMAC-SHA256 token authentication.

You stay in control

Remove the probe anytime from your dashboard. Revoke the API key instantly to disable access.

What the probe inspects 36

Plugin & Update Health
Sensitive File Exposure
Admin Panel Access
Known Vulnerabilities
CMS-Specific Security
Composer Dependencies
Cron Job Health
Database Optimization
Database Performance
Database Security
Debug Mode Detection
Default Credentials & Secrets
Directory Listing
Environment & Sensitive Files
Error Handling Configuration
CMS Core File Integrity
File Permissions
Server-Side Compression
HTTP Redirect Configuration
Error Log Analysis
Email Authentication
PHP Memory & Execution Limits
Object Cache
OPcache Configuration
Exposed Service Ports
PHP Configuration
PHP Extensions
PHP Version End-of-Life
Server Resources
Server Configuration
Session Security
SSL/TLS Certificate
Temporary Directory Security
Web Server Fingerprinting
WordPress REST API Exposure
XML-RPC Access
Included Free

SEO Intelligence included

Every analysis includes a full SEO Intelligence report — organic traffic, ranked keywords, backlinks, competitors, and brand mentions.

  • Organic traffic & keyword rankings
  • Backlink profile & referring domains
  • Competitor landscape analysis
  • Brand mentions & sentiment tracking

Domain Overview

42.5

Domain Rank

12.4K

Organic Traffic

847

Organic Keywords

Ranked Keywords

web audit tool
2.4K #3
site performance check
1.8K #7
seo analyzer free
5.1K #12
Real-time Monitoring

Never miss a downtime again

24/7 uptime monitoring with instant alerts. Know when your site goes down before your users do.

  • Checks every 5 minutes with response time tracking
  • Instant email alerts when your site goes down
  • 30-day availability charts with incident timeline
  • HTTP status code and response time monitoring
Learn more

99.8%

Uptime (30 days)

245ms

Avg Response

30 days ago Today
Online Last check: 2 min ago
14:32 UP 231ms
14:27 UP 248ms
14:22 DOWN
Server Monitoring

Know what's happening inside your server

Go beyond HTTP checks. Monitor CPU, memory, disk, and services in real-time with the WMSS probe installed on your server.

  • Real-time CPU, RAM, and disk usage tracking every 5 minutes
  • MySQL, Redis, PHP-FPM, Apache & Nginx service monitoring
  • Predictive alerts — get warned before your disk is full
  • Public status page with services and system metrics
Learn more
All systems healthy Last check: 2 min ago
MySQL
Redis
PHP-FPM
Nginx
Apache
Memcached
CPU 72%
RAM 58%
Disk 38%
Memcached is down — alert sent via Slack
Google Integration

Search Console, Analytics & Performance in one dashboard

Connect your Google accounts once. We pull everything automatically — keywords, traffic, Core Web Vitals, PageSpeed scores, and more.

  • Google Search Console — day-by-day keyword positions, clicks & CTR
  • Google Analytics 4 — sessions, devices, sources, events & real-time visitors
  • Core Web Vitals — LCP, INP, CLS with 6-month trend history
  • PageSpeed Insights — Lighthouse scores with actionable opportunities
  • URL Inspector — check any page's indexing status instantly
  • Geographic & device breakdown — know where your traffic comes from
  • Audit Impact — measure real traffic changes after each audit
  • Period comparison with automatic deltas vs previous period
Learn more
12 active users right now

Sessions

12,450

+18%

Users

8,320

+12%

Engagement

78.5%

+2.3%

Bounce

21.5%

-1.2%

Overview Acquisition Content Behavior

Channels

Organic
72%
Direct
18%
Referral
6%
Social
4%

Devices

Desktop 72%Mobile 24%Tablet 4%
72

Perf

89

A11y

95

BP

82

SEO

AI Search Tracking

Track, analyze & optimize your AI visibility

See exactly which AI engines mention and cite your brand — and get actionable recommendations to improve.

  • Query Tracker — see if ChatGPT, Claude, Gemini & Perplexity cite you
  • Citation Gap Analysis — find which sources are cited instead of you
  • Content Optimizer — get actionable recommendations to improve visibility
  • Brand Narrative — understand how AI engines describe your brand
  • Share of Voice — compare your visibility against competitors
  • Auto-generated queries from your Google Search Console keywords
  • AI Search Volume — discover what LLMs search about your topics
  • 30-day trend tracking with per-provider scoring breakdown
Learn more
Score 72
|
Queries 15
|
Mentions 68%
|
Citations 45%
Overview Queries Citations Gaps Competitors Optimizer Brand
Query ChatGPT Claude Gemini Perplexity
best audit tool ✓ #2 ✓ #1 ✓ #3
seo analyzer ✓ #1
site checker ✓ #1 ✓ #1 ✓ #2 ✓ #1

Citation Gaps

competitor.com 18x
wikipedia.org 12x
You 3x

Brand Attributes

reliable trusted professional fast quality
Simple, transparent pricing

Simple, transparent pricing

Start free, upgrade when you need more power.

Starter

$0

Quick frontend audits. No account required.

  • 3 audits/month
  • Backend audits (probe)
  • PDF report export
  • Vulnerability alerts (0 sites)
  • Uptime monitoring 24/7
  • Server monitoring
  • Google Analytics & Search Console
  • AI Visibility tracking
  • Scheduled audits ()
  • White-label reports
  • Client portal
  • Team management (0 members)
  • Multi-site comparison
  • REST API access
  • Priority support
Start for free
Most popular

Pro

$29 /mo

Backend audits, PDF exports, vulnerability alerts.

  • 15 audits/month
  • Backend audits (probe)
  • PDF report export
  • Vulnerability alerts (5 sites)
  • Uptime monitoring 24/7
  • Server monitoring
  • Google Analytics & Search Console
  • AI Visibility tracking
  • Scheduled audits ()
  • White-label reports
  • Client portal
  • Team management (0 members)
  • Multi-site comparison
  • REST API access
  • Priority support
Get Pro

Agency

$79 /mo

White-label, client portal, scheduled audits, team.

  • 50 audits/month
  • Backend audits (probe)
  • PDF report export
  • Vulnerability alerts (25 sites)
  • Uptime monitoring 24/7
  • Server monitoring
  • Google Analytics & Search Console
  • AI Visibility tracking
  • Scheduled audits (weekly)
  • White-label reports
  • Client portal
  • Team management (3 members)
  • Multi-site comparison
  • REST API access
  • Priority support
Go Agency

Enterprise

$199 /mo

API access, priority support, maximum capacity.

  • 200 audits/month
  • Backend audits (probe)
  • PDF report export
  • Vulnerability alerts (100 sites)
  • Uptime monitoring 24/7
  • Server monitoring
  • Google Analytics & Search Console
  • AI Visibility tracking
  • Scheduled audits (daily)
  • White-label reports
  • Client portal
  • Team management (10 members)
  • Multi-site comparison
  • REST API access
  • Priority support
Get Enterprise

Managing multiple client sites? Discover WMSS for agencies →

FAQ

Frequently asked questions

Everything you need to know about our web audit platform.

Yes. The frontend audit is 100% free, with no account required. You get a full report covering performance, security, SEO, accessibility, and best practices.
The Pro plan unlocks deep backend analysis via a persistent read-only probe on your server. It checks PHP configuration, database performance, file permissions, server security, and CMS-specific vulnerabilities — with continuous monitoring.
The probe is a single PHP file that only reads configuration data. It never modifies files or databases. It stays on your server for continuous monitoring, secured by a unique API key.
A free frontend audit completes in about 60 seconds. A full backend audit takes 2-3 minutes.
We detect and provide specialized checks for WordPress, Magento 1 & 2, PrestaShop, Drupal, and Joomla. The general checks work on any website.

Still have questions?

Our team is here to help — reach out anytime.