Skip to content

Website audits

Prove what a website needs, in a report you can put your name on.

Every check runs live against the site and is measured against a standard the reader can look up. The findings are ranked by the service you sell, costed in money, and written for the person who owns the business rather than the person who built the site.

Measure, rank, explain

Three steps between a URL and a document a business owner will read to the end.

Measure

Every check in the engine, run live against the site, each one reporting whether it ran, found nothing, failed, or was never available here.

Rank

11 weighted categories into one number and a letter grade, with the weights set by the service line you sell.

Explain

A 17-section report written for the person who owns the business, with the fix, the cost and the evidence beside every finding.

Evidence

Every finding shows the measurement, the standard and the source.

A report is only as strong as the one finding a client decides to question. So each one carries what was measured, the published threshold it was measured against, how it was obtained, and when. Nothing is a verdict you have to take on trust.

How we measure
Against something published
Core Web Vitals, WCAG 2.1 AA, the TLS and email-authentication standards. The reader can look the threshold up.
Measured or inferred, and it says which
A confidence label on every finding, printed rather than smoothed over.
PERFORMANCE Mobile LCP 5.4s 0 2.5s good 8s CORE WEB VITALS MEASURED 25 SEP

Your name is on this report

A check that could not run is not a check that passed.

You put your logo on this and send it to a client. So when something could not be measured, the report says so, in one of five states per check, printed, every time. The alternative is a green tick you cannot stand behind in the room.

47 checks ship in the engine. Which of them run against a given site depends on the plan, on what the site turns out to be, and on what the deployment has installed, so the report says which, every time.

ok
It ran and it produced a measurement.
empty
It ran, and there was nothing to report. Clean, not absent.
failed
It tried and could not finish. The only one of the five that means something is wrong at our end.
missing
The tool behind it is not installed on this deployment, so the check was never available.
skipped
Deliberately excluded, either by the plan tier or by the gate that stops a heavy scan running against a domain with no site on it.

Ranking

Same audit. Ranked for the service you sell.

A list of forty problems is not a report. The scoring weights are a profile, so a web studio, an SEO consultancy and a security provider each get the same measurements in the order that matters to their work, and the report opens with the thing worth fixing first.

How the scoring works
Weighted by what you sell
Pick a profile and the findings reorder themselves around it. The measurements do not change; the priorities do.
Costed, not just counted
Each finding carries an estimate of what it plausibly costs the business, with the assumptions shown.
ONE AUDIT · THREE RANKINGS WEB DESIGN 1 CONVERSION 2 SPEED 3 ACCESS 4 SEO SEO 1 SEO 2 AI VIS 3 SPEED 4 CONVERSION SECURITY 1 SECURITY 2 TECH 3 SPEED 4 SEO

What gets measured

11 categories, each against something published.

Grouped into five tabs here for reading; the report scores each category separately. Every number in it is a live measurement of the site in question, checked against a standard the reader can go and look up, and that constraint is what makes a diagnostic arguable rather than merely assertive.

Core Web Vitals, lab and field

Measured in a real headless browser and, where enough real visitors exist for it, against the field data Google collects from them. Server response time, render timings, layout stability, and the weight of what the page is actually shipping.

Read-only, first-party, GET requests

Response headers graded, TLS protocol and certificate chain, configuration files and debug surfaces left reachable, credentials matched inside the JavaScript the site publishes, and known vulnerabilities in the client-side libraries it loads. Nothing is written and no payload is injected. Email authentication scores here too, not as a category of its own: SPF, DKIM, DMARC and BIMI, and whether the sending domain has ended up on a mail blacklist. "Your invoices are going to spam" costs money this month in a way a missing header does not, and no other tool in this category looks at it.

For search engines and for answer engines

Titles, headings, canonicals, structured data and sitemap validity. Then the two AI questions separately, because they are two questions: whether an answer engine is allowed to read the site at all, and whether there is anything on it worth citing when it gets in, which is authorship, dates, citations and a defined business entity.

The business, not just the website

The Google Business Profile scored on its own: claimed or not, hours, categories, photos, and whether the listing says the business has closed. Beside it the public review corpus with its recurring complaints, and how well the business surfaces in map results across the area it actually serves. For a business with no website at all this is the only part of the audit that can produce a score, and an unclaimed listing is the one fix that unlocks every other fix there is.

Whether a visitor can use it, and what it is made of

WCAG 2.1 AA failures counted on the rendered page by severity, alongside the practical things: whether there is a call to action, whether the form works, whether a phone number can be tapped, and what stands between a visitor and an enquiry. Then what built the site and what hosts it, fingerprinted separately because they are separate facts, and the build-quality signals a hurried site leaves behind: JavaScript errors thrown at real visitors, dead-code bloat, and placeholder copy still on the page.

Everything measured about a business, beyond its website

The audit is one of several things measured about a business. The rest is what tells you whether the site is the problem or a symptom of one.

Reviews, read rather than counted

The public review corpus with its sentiment, the complaints that come up more than once, and what customers praise. A star count is not a finding; "four people mention the phone going unanswered" is.

Local search visibility

How well the business is surfaced in local results, verified directories, and map listings, and where that sits against the others in its trade.

The presence behind the site

Which social profiles a business actually keeps live, read off the pages it links to itself. Ordinary HTTP, with no data broker and nothing that requires logging in to a platform. A dormant account is a finding in the reputation score; it is not a way to contact anybody.

Two segments, two problems

A business with no website at all is a different case from one whose website is in trouble, and they are counted separately. Each also carries what it is standing on instead: a social page, a directory, a builder.

What built it, and what hosts it

Fingerprinted separately, because they are separate facts. The report then speaks in the terms of the tool the owner actually used rather than in terms of a stack they have never heard of.

The report

17 sections, and none of them assume a developer is reading.

The web report and the PDF are always identical: what you show on a call matches what you email. From the Pro plan up it carries your logo, your colour and your name.

Read a sample report
Why, what it costs, how to fix
Every warning carries all three, in plain sentences, with an effort estimate you can price.
A confidence label per finding
High where it was measured, medium where it was inferred, and the report says which.
A shareable link and a PDF
Unguessable, no login, opens on a phone. Views are counted, because somebody re-reading a report is a signal.
Before and after
Re-audit later and the two are diffed, which is how you show a client what they paid for.

From finding to fixed

A diagnosis nobody can act on is a document, not a deliverable.

Most of this category stops at the finding. The gap between "your SPF record is wrong" and a client with a working SPF record is where an agency actually earns, so the report closes as much of it as it can.

The fix, already written
The nginx block, the schema snippet, the SPF record for the mail provider they are actually on. Paste it, do not translate it.
And a prompt for their AI agent
Every fix also ships as a paste-ready instruction for the assistant that will make the change. Nobody else in this category does this, and it is increasingly how the work gets done.
What it plausibly costs them
A monthly figure, with every assumption behind it returned in the same breath rather than buried. A number you cannot show your working for is a number that loses the room.
Three grades a buyer already asks for
AI readiness, email security, and compliance, each A to F, each naming exactly which factors are missing. Plus an external attack-surface grade from what is reachable from outside.

The part nobody else ships

Every fix also comes as a prompt for the agent that will make it.

A findings list assumes a developer reads it and translates. Increasingly nobody does: the person fixing the site opens an assistant and describes the problem badly. So each finding ships a third form beside the explanation and the snippet, written to be pasted straight into a coding agent, carrying the measured value and the constraint rather than a vague instruction. It is the difference between a report that gets read and one that gets acted on the same afternoon.

Attached to the DMARC finding on a real report

Add a DMARC record to example.com.

Current state, measured 2026-09-06: SPF passes, DKIM passes,
no _dmarc TXT record exists. Mail provider is Google Workspace.

Add this TXT record at _dmarc.example.com:

  v=DMARC1; p=none; rua=mailto:dmarc@example.com; fo=1

Start at p=none so nothing is rejected while you read the
reports. Do not move to p=quarantine until the aggregate
reports show every legitimate sender aligned, which is
usually two to four weeks.

Do not change the existing SPF or DKIM records. Both pass.

Monitoring

Re-run on a schedule and the report says what moved.

A report is read once. A monitored site is a reason to talk every month: the score climbing as the fixes land, and an alert the week a deploy undoes one. Before and after are diffed, which is how you show a client what they paid for.

See pricing
Scheduled audits
Weekly or monthly, on the plans that include monitoring, with only the changes sent to you.
Told when it matters
A monitored site that moved, a report somebody is re-reading, and one daily digest. Nothing else.
WEEKLY RE-AUDIT 41 → 72 LCP +1.2s WK 1 WK 8

AI shipped it. Nobody checked the deploy.

A distinct and growing segment: sites assembled quickly by somebody who is not a developer, working through an assistant. They are usually well designed and they frequently publish things that were never meant to leave the server. Each of these is also a free tool on this site, so you can run one against a site you already know before you take our word for any of it.

Keys in the bundle

Provider credentials matched inside the JavaScript the site hands to every visitor. Published, not hidden.

Rows anyone can read

A database with row-level security never switched on, read using the public key the app ships itself. Read-only requests, nothing written.

Source maps in production

The file that turns a minified bundle back into the code somebody wrote, left reachable on the live site.

Scaffolding left in

Placeholder copy still on the page, the visible half of the same haste that left the rest of this list behind.

Which builder made it

Builder and host fingerprinted separately, so the report speaks in the terms of the tool the owner actually used rather than a stack they have never heard of.

Can an answer engine read it

Whether AI crawlers are allowed in at all, and whether there is anything quotable when they arrive. Generated sites are frequently one and not the other.

What a scanner does not do

Not a feature count. A few places where this behaves differently from the thing you are probably also evaluating, each of them a decision rather than a gap somebody has not got round to.

Capability SiteAssay A typical audit tool
A check that could not run One of five states, printed on the report Counted as a pass
What the finding costs An estimate in money, printed beside the measurement A severity colour
Email deliverability SPF, DKIM, DMARC, BIMI, and whether the domain is blacklisted Not looked at
Their competitors The site and up to three rivals, same pass, same scale One site at a time
From an AI agent An MCP server that can start the audit, not only read one Read-only, where it exists at all
Whose name is on it Yours: logo, colour and footer. Ours disappears entirely Theirs, with your logo in a corner

Questions

What does the audit measure?

11 categories, each scored against a published standard: speed, security, search, AI visibility and trust, conversion, accessibility, technology, reputation, the Google Business Profile and build quality. Every number is a live measurement of the site in question.

What happens when a check cannot run?

The report says so. Each check ends in one of five states and the state is printed, so a check that never ran is never shown as a pass.

Can I put my own name on the report?

Yes, from the Pro plan up. Your agency name, logo and colour replace ours on the web report and the PDF.

Can I audit a site without an account?

Yes. The free audit runs without an account, and you can buy the full report for that one site for $19 with nothing to cancel.

Try it on a site you already know

The fastest way to judge an audit engine is to point it at a website whose problems you can already list, and see how many of them it finds.