Free Website Audit
Your Website Has Bugs You Don't Know About
We Find Them
Most QA tools require you to write tests. This one doesn't - point it at any website and it crawls every page automatically, checking dozens of things that silently hurt your visitors and your search rankings.
What gets checked
Every Page. Every Issue. Nothing Missed.
85+ distinct checks, most running on every crawled page across three viewports
Per-Page Checks
- Run on every crawled page - desktop, tablet, and mobilePerformance
- HTTP status code (200 expected) - desktop, tablet, mobile
- Page load time - desktop, tablet, mobile
- First Contentful Paint (FCP)
- Largest Contentful Paint (LCP)
- Cumulative Layout Shift (CLS)
- Time to First Byte (TTFB)
- Total page weight (threshold: 3 MB)
- Total HTTP request count (threshold: 100)
- HTML compression (gzip/Brotli)
- Redirect hop count (threshold: 2)
Layout & Responsiveness
- Horizontal scroll / layout overflow - desktop, tablet, mobile
- JS console errors - desktop, tablet, mobile
- JS console warnings (logged, not flagged as failures)
- Mixed content (HTTP resources on HTTPS page)
Images
- Broken images
- Missing alt text
- Missing width/height attributes (causes layout shift)
- Below-fold images missing loading="lazy"
- Oversized images (not sized appropriately for display)
- Modern image format usage (WebP/AVIF)
Links
- Broken internal links
- Broken external links
- Broken anchor links (#fragment pointing to non-existent ID)
Content
- Word count (minimum 300 words)
- Placeholder "lorem ipsum" text
- Key phrases present (configurable)
- Navigation element present
- CTA / button elements present
- Footer present
- Copyright year current
SEO & Metadata
- Page title (present, 4-60 chars)
- Meta description (present, 11-160 chars)
- OG title, OG description, OG image
- Canonical tag
- Hreflang tags (for multi-language sites)
- Noindex meta tag (accidental indexing block)
- H1 present, exactly one
- Heading hierarchy (no skipped levels, e.g. H1→H3)
- HTML lang attribute
- Viewport meta tag
- Favicon
- Structured data / JSON-LD present
- Duplicate titles across pages
- Duplicate meta descriptions across pages
Security & Integrity
- CSS/JS assets loading (no 4xx/5xx)
- Subresource Integrity (SRI) on third-party scripts/styles
Accessibility
- Axe-core scan (critical and serious violations)
- Skip navigation link (WCAG keyboard requirement)
- Touch target sizes (44×44px minimum, WCAG 2.5.5)
Forms & Auth
On pages that have them
- Form fields present and fillable
- Submission triggers expected API call
- Thank-you page / success state reached
- Signup vs. login form detection
- SSO login button detection (Google, Microsoft, GitHub, etc.)
Site-Level Checks
- Run once across the entire siteTech Stack Detection
- CMS identification
- Hosting / CDN provider
- JS framework detection
- Installed plugins
- Analytics & tracking tools
- Payment processors
- E-commerce platform
Infrastructure
- HTTP → HTTPS redirect
- www → non-www redirect consistency
- sitemap.xml accessible
- robots.txt accessible and not blocking crawlers or the sitemap
- SSL certificate validity and expiry
- DNS resolution
E-Commerce Testing
Runs when a store is detected
- Cart and checkout reachability
- Add-to-cart button presence across every product page found
- 25+ payment processors detected (Stripe, PayPal, Klarna, Afterpay, Apple/Google Pay, crypto processors, and more)
Security
- HSTS header
- X-Content-Type-Options
- X-Frame-Options
- Content-Security-Policy
- Referrer-Policy
- Permissions-Policy
- Cookie security flags (Secure, HttpOnly, SameSite)
- Cookie consent banner presence
- Directory listing disabled on common paths (/images/, /assets/, etc.)
The Report
A clean PDF report: an executive summary and top-priority callout up front, a site intelligence snapshot (tech stack, hosting, SSL, DNS), a security context section explaining why each finding matters for your type of site, a page-by-page summary, and a full detailed appendix with every issue found and enough detail to act on immediately.



