security-headers |
Checks six security response headers (HSTS, CSP, X-Content-Type-Options, etc.). |
security-headers.md |
ssl-tls-check |
Certificate validity, protocol strength, and HSTS preload signals. |
ssl-tls-check.md |
dns-health |
DNS record resolution (A/AAAA/MX/CNAME/TXT) and lookup performance. |
dns-health.md |
robots-txt |
robots.txt presence, parsing, sitemap reference, and risky bot rules. |
robots-txt.md |
sitemap-validation |
XML sitemap fetch/parse, sampled URL checks, and freshness hints. |
sitemap-validation.md |
seo-meta-tags |
Title, meta description, H1, canonical, Open Graph, JSON-LD; multi-page when crawl data exists; optional keyword coverage. |
seo-meta-tags.md |
cookie-compliance |
Tracking cookies vs consent signals and cookie security flags. |
cookie-compliance.md |
response-time |
HTTP latency samples with configurable percentile thresholds. |
response-time.md |
mixed-content |
HTTP subresources on HTTPS pages (mixed content). |
mixed-content.md |
open-port-scan |
TCP probes for unexpected open ports (excludes 80/443). |
open-port-scan.md |
sensitive-file-exposure |
HEAD probes for sensitive paths (.env, .git, backups, admin panels). |
sensitive-file-exposure.md |
image-optimization |
Image sizing, formats, lazy loading, and alt text via HTTP. |
image-optimization.md |
analytics-audit |
Tag managers, analytics, pixels, consent mode, blocking scripts, and tracker inventory. |
analytics-audit.md |
ga4-data-health |
GA4 API health: real-time users, daily metrics, drops, and broken tracking signals (requires service account secret). |
ga4-data-health.md |
ai-search-readiness |
llms.txt, AI crawler rules in robots.txt, structured data depth, and snippet-oriented signals. |
ai-search-readiness.md |
ai-citability-check |
Passage-level scoring for AI citation readiness across sampled pages. |
ai-citability-check.md |
redirect-chain |
Redirect chains, loops, length, and permanent vs temporary redirects. |
redirect-chain.md |
structured-data-validator |
JSON-LD / rich results-oriented structured data validation. |
structured-data-validator.md |
http-protocol-check |
HTTP/2 and HTTP/3 (QUIC) advertisement and negotiation checks. |
http-protocol-check.md |
email-auth-check |
SPF, DMARC, and DKIM policy signals for outbound mail. |
email-auth-check.md |
cache-header-audit |
Caching headers on HTML and static assets (Cache-Control, ETag, Vary, etc.). |
cache-header-audit.md |
cors-audit |
CORS preflight and policy checks on the target and common API paths. |
cors-audit.md |
csp-deep-audit |
Deep Content-Security-Policy analysis beyond header presence. |
csp-deep-audit.md |
payment-gateway-health |
Detects payment SDKs in HTML and probes gateway reachability/latency. |
payment-gateway-health.md |
w3c-html-validation |
W3C Nu Html Checker validation for the target and optional internal pages. |
w3c-html-validation.md |
soft-404-check |
Detects soft-404 responses and grades real error-page UX. |
soft-404-check.md |
compression-check |
Checks Content-Encoding / Vary on HTML and static assets. |
compression-check.md |
security-hygiene |
RFC 9116 security.txt presence/validity and third-party SRI attributes. |
security-hygiene.md |
legal-compliance-no |
Norwegian legal/compliance signals (org number, contact, etc.). |
legal-compliance-no.md |
social-preview-check |
Open Graph / Twitter card preview image and metadata checks. |
social-preview-check.md |
domain-reputation |
DNSBL / reputation signals for the domain and mail infrastructure. |
domain-reputation.md |
safe-browsing |
Google Safe Browsing threat status for the target URL. |
safe-browsing.md |
crux-field-data |
Chrome UX Report field metrics for the origin when available. |
crux-field-data.md |
pagespeed-insights |
PageSpeed Insights lab/field scores via the PSI API. |
pagespeed-insights.md |
magento-custom-options-hygiene |
Magento-gated checks: custom_options path deny, PHP execution under that tree, and known PolyShell IoC filenames (no uploads). |
magento-custom-options-hygiene.md |