SiteScanFix
Continuous audit13 scanners

Operational evidence
for your web surface.
Signed. Dated. Defensible.

Security, SEO, performance & accessibility — one report, plain English, actionable fixes. Built for security, compliance and engineering teams who need to answer the same question across every property they ship.

https://
GDPR · DPDPIndia DPDP compliantNo installs~10 min report
Sample report · R-22841-ASigned
70Score
acme-corp.com
Last scan · 2026-05-17 · 12:42 UTC
2 critical4 high7 passed
Security
58
Perf
91
SEO
84
A11y
67
F-104 ·Missing Content-Security-Policy headerCRITICAL
F-117 ·3 third-party trackers without consentHIGH
F-129 ·Two cookies set without Secure attributeHIGH
F-201 ·HSTS configured · max-age 63072000PASSED
13
scanners run in parallel
<10 min
median report delivery
100%
automated — no installs
3 free
scans to start, no card
13 scanners · one report

Every layer of your site — checked

Most tools check one thing. We run 13 simultaneous checks and return a structured, severity-ranked report — no technical knowledge required.

Security

SSL/TLS grade, HTTP security headers, CORS policy, exposed files (.env, .git, admin panels), cookie flags, DNS security (SPF/DMARC/DKIM/MTA-STS), known JS CVEs, mixed content and Subresource Integrity (SRI).

Performance

Google PageSpeed Insights score, First Contentful Paint, Largest Contentful Paint, Total Blocking Time, Cumulative Layout Shift — powered by Google's infrastructure for consistent, reliable results.

SEO

Google PageSpeed Insights SEO score + our own content audit: page title length, meta description, H1 structure, image alt text coverage, canonical URL, Open Graph tags and Twitter Card — the details Google actually cares about.

Accessibility

Full WCAG 2.1 audit via Google PageSpeed Insights and axe-core: contrast ratios, missing ARIA labels, keyboard traps, skip links and form labels — violations ranked by severity.

Privacy & GDPR Compliance

Detects advertising, analytics and social media trackers loaded on your page. Flags GDPR / India DPDP risk and tells you exactly which third parties need a consent banner before they can load.

Technology Fingerprinting

Identifies the CMS, frameworks, CDN, analytics tools, payment processors and server software your site uses — from HTTP headers, HTML patterns and loaded scripts. Useful for security review and vendor auditing.

All 13 scanners — by capability
Security
  • SSL / TLS Certificate
  • HTTP Security Headers
  • CORS Configuration
  • Sensitive File Exposure
  • JavaScript CVE Detection
  • Mixed Content & SRI
DNS & Email
  • DNS & Email Security
  • Cookie Flags
SEO & Content
  • SEO Content Audit
  • Performance & SEO (PageSpeed Insights)
Performance
  • Performance & SEO (PageSpeed Insights)
Simple process

How it works

01
Paste your URL

Any public website. Accept two quick consent checkboxes required by India's DPDP law.

02
13 scanners run simultaneously

Google PageSpeed Insights, axe-core, SSL Labs, retire.js, GDPR tracker detection, tech fingerprinting and more — all at the same time.

03
Read your plain-English report

Scores, severity-ordered findings, AI-written summary and a downloadable PDF — no jargon, no guesswork.

Procurement-ready

Compliance & trust

Built for teams that need to answer compliance questions, not just pass a checkbox. Audit evidence you can actually use.

GDPRActive
GDPR & DPDP-2023

EU and India data protection. Dual consent gates, 90-day retention, right to deletion.

DPO · support@sitescanfix.com

SOCPlanned
SOC 2 Type II

Security, availability and confidentiality criteria.

In preparation · 2026

CSPActive
CSP-aligned headers

Every header recommendation references OWASP and RFC standards — not opinion.

OWASP reference

ISOAligned
ISO 27001 aligned

Control mapping included in Agency plan reports. Not ISO-certified.

Evidence export available

Start in 60 seconds

Run your first audit — free

No installation, no browser extension. Paste a URL, accept two consent checkboxes required by India's DPDP law, and get your report in under ten minutes.

https://
Data residency

Scan results stored in EU by default. India region available on request.

90-day retention

Report data auto-deleted after 90 days per DPDP requirements. Delete on demand from your dashboard.

DPA on request

Data Processing Addendum available for enterprise and agency plans. No email gate.

Transparent cost

Flat monthly rate. No per-scanner fees, no hidden costs. Agency plan caps at 300 scans/month to protect margin.