Eye4Tech

Free website audit — 60+ checks for exposed files, security headers and SEO.

01

Exposed files

Backups (.zip, .tar.gz), database dumps (.sql), .env secrets, Git metadata, config backups, logs, open directories and leftover admin tools — each confirmed by content, not just a 200 status.

02

Security posture

HTTPS and redirects, HSTS, Content-Security-Policy, clickjacking and MIME-sniffing protection, cookie flags, mixed content, and software versions leaking in headers.

03

SEO fundamentals

Title and description length, H1 structure, whether your headline actually matches what the page talks about, canonical, viewport, alt text, Open Graph, structured data, robots.txt, sitemap and soft-404s.

04

Performance signals

Server response time, compression, page weight, render-blocking scripts, stylesheet count and images without dimensions — the inputs to Core Web Vitals.

How it works

Rules, not guesses.

Every check is a fixed rule with a fixed threshold — the same site gets the same result every time, and every finding tells you exactly what was seen. Nothing here is generated or estimated.

Is this safe to run on my live site?
Yes. The scan makes a small number of ordinary GET requests, the same kind a browser makes: your homepage, robots.txt, sitemap.xml, one deliberately non-existent page, and a fixed list of well-known file paths. It never logs in, never submits forms, never runs scripts against you, and downloads at most a few kilobytes of any file it probes. Requests are rate-limited so the load is negligible.
Why does it only check the homepage?
Because it has to finish in under a minute and be free. The homepage carries most of the site-wide problems — headers, HTTPS, exposed files at the web root, robots and sitemap — and the on-page SEO rules show you the pattern your other pages almost certainly share. A full crawl of every page is what we do in a paid audit.
What does "confirmed by content" mean for exposed files?
Many websites answer "200 OK" with a friendly page for any address you type, so a 200 on /backup.zip proves nothing. We only report a file as exposed when the response actually looks like the file: a ZIP starts with the right bytes, a database dump contains CREATE TABLE statements, an .env file has KEY=value lines, a Git file starts with ref:. That is why the results are worth acting on.
Does a good score mean my site is secure?
No. It means none of these specific, common, externally visible problems were found. It says nothing about your application code, your admin passwords, your hosting account or your dependencies. Treat it as a first filter — the things an attacker would try in the first five minutes — not a penetration test.
Do you keep the results?
The report is generated on the fly and shown to you. We log that an audit was run and for which domain, so we can follow up if you book a call; we do not store the findings.
Book free consultation Send details