Free website audit — 60+ checks for exposed files, security headers and SEO.
Reaching the site…
Fetching the homepage, robots.txt and sitemap, then probing 47 sensitive paths and running the security, SEO and performance rules.
Exposed files
Backups (.zip, .tar.gz), database dumps (.sql), .env secrets, Git metadata, config backups, logs, open directories and leftover admin tools — each confirmed by content, not just a 200 status.
Security posture
HTTPS and redirects, HSTS, Content-Security-Policy, clickjacking and MIME-sniffing protection, cookie flags, mixed content, and software versions leaking in headers.
SEO fundamentals
Title and description length, H1 structure, whether your headline actually matches what the page talks about, canonical, viewport, alt text, Open Graph, structured data, robots.txt, sitemap and soft-404s.
Performance signals
Server response time, compression, page weight, render-blocking scripts, stylesheet count and images without dimensions — the inputs to Core Web Vitals.
Full report
Get the fixes — free full report by email.
The report includes every issue above with the exact fix for each, plus the checks that passed, ready to hand to your developer. No follow-up spam.
Want these fixed properly?
Book a free 30-minute consultation and a senior engineer will walk through this report with you — what matters, what can wait, and what it would take. No obligation.
How it works
Rules, not guesses.
Every check is a fixed rule with a fixed threshold — the same site gets the same result every time, and every finding tells you exactly what was seen. Nothing here is generated or estimated.
Is this safe to run on my live site?
Why does it only check the homepage?
What does "confirmed by content" mean for exposed files?
ref:. That is why the results are worth acting on.