How does a site present itself to AI? Per-crawler robots.txt verdicts for 13 major AI user agents (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot and more), llms.txt presence and shape, sitemap signals, and a concrete fix list. Charged only when the audit completes.
A full DNS record inventory (A, AAAA, MX, NS, TXT, CAA, SOA, CNAME) over DNS-over-HTTPS, with the misconfigurations that matter flagged: missing CAA, no MX, apex CNAME, missing SPF/DMARC, no IPv6, no DNSSEC, single nameserver. Charged only on completed audits.
Registration age, expiry, registrar, status flags, nameservers, and DNSSEC for any domain via RDAP over HTTPS - the modern replacement for port-43 WHOIS. Flags newly-registered domains, imminent expiry, hold/pending-delete states, and missing DNSSEC. Charged only on completed lookups.
Brand protection in one call: generate lookalike domains for a brand (typos, transpositions, homoglyphs, hyphenation, TLD swaps) and check via DNS which are actually registered. The registered lookalikes are your threat list for phishing and brand abuse. Charged only on completed audits.
SPF, DKIM, DMARC, and MX for any domain, parsed and graded A-F with a concrete fix list: enforcement qualifiers, lookup-limit risk, DMARC policy strength, missing DKIM selectors. The interpretation layer raw DNS lookups don't give you. Charged only when the audit completes.
Verify a list of email addresses without sending mail. Combines syntax checks, MX lookup over DNS-over-HTTPS, disposable and role-account detection, and an optional live SMTP mailbox probe into a per-address verdict: valid, invalid, risky, or unknown. Charged only on completion.
Can search engines index this page, and if not, why? Checks the meta robots tag, X-Robots-Tag header, canonical link, and robots.txt in one call and returns a plain verdict with the exact directive responsible. Charged only on completed audits.
A ready-to-review llms.txt draft for any site, built deterministically from its own sitemap, titles, and meta descriptions. No model, no invented copy: every line traces to the site itself. Saved as a downloadable llms.txt file. Charged only on completed generations.
Monitor any Model Context Protocol server for change: each run snapshots the endpoint and diffs it against the last snapshot - tools added, removed, or changed, version bumps, latency drift. Schedule it and know the moment a dependency's contract moves. Charged only when a probe completes.
Handshake, tool inventory, and latency for any Model Context Protocol server over streamable HTTP: server info, capabilities, every tool with its input schema, session mode, auth behavior. Charged only when a probe completes.
Fetch an OpenAPI or Swagger spec (JSON or YAML) and get a graded A-F verdict: operation inventory, undocumented operations, missing responses and operationIds, security coverage, and duplicate operationIds. Charged only on completed audits.
A performance read without a headless browser: parse the HTML, measure every script, stylesheet, and image by transfer size, total the page weight, and flag render-blocking resources, uncompressed assets, and oversized images. Charged only on completed audits.
Fetch a page, isolate its main text, and score it: Flesch Reading Ease, Flesch-Kincaid grade, Gunning Fog, sentence and word statistics, complex-word density, and the specific long sentences to fix. Deterministic, no model. Charged only on completed audits.
Follow every redirect hop for a list of URLs and report what SEO tools miss: multi-hop chains, loops, HTTPS-to-HTTP downgrades, temporary redirects where permanent ones belong, and chains ending in errors. Each URL gets its full observed chain. Charged only on completed audits.
Feed discovery, validity, and freshness for any site: feeds declared in the HTML head and at common paths, XML parsed as RSS or Atom, item counts, newest-item age, empty-title hygiene, and whether readers can auto-discover the feed at all. Charged only on completed audits.
One GET, a graded A-F verdict on the security headers browsers enforce: HSTS, CSP (unsafe-inline detection), X-Content-Type-Options, frame protection, Referrer-Policy, cookie flags, HTTPS, version disclosure. Each failure gets a concrete fix. Charged only on completed audits.
Can a site's sitemap be trusted? Discovery via robots.txt and common paths, XML validity, index nesting, lastmod coverage and freshness, over-limit warnings, and a dead-URL sample check. Extraction tools list URLs; this grades the sitemap. Charged only when the audit completes.
Will your links unfurl correctly on social and chat platforms? Open Graph tags, Twitter card, canonical, and title/description lengths checked per URL, with og:image actually verified reachable, not just present. Specific issues per URL. Charged only on completed audits.
A real TLS handshake graded A-F: days until expiry, chain validity, hostname match, protocol and cipher, issuer, SAN coverage. Expired, self-signed, and wrong-host certs each get a precise verdict. Schedule it to catch expiries early. Charged only on completed audits.
Extract and validate a page's JSON-LD, report the schema.org types present, and flag missing recommended properties that block rich results and AI grounding. Detects microdata, RDFa, and Open Graph too. Charged only on completed audits.
Finds dead internal links on any WordPress site: reads content via the public REST API, checks every internal link it references, and reports each broken one with the pages that link to it. Charged only when a check completes.
Inventory and score any WordPress site: word counts, thin-content flags, missing excerpts, staleness. Reads only the public REST API. Outcome-based: no charge unless the audit completes.
Accessibility and image-SEO audit for any WordPress site: every image missing alt text, with the page it lives on, plus coverage percentages and the worst pages. Distinguishes missing alt from valid decorative alt="". Charged only when an audit completes.