Six checks, one crawl, one document
Each check reports what an automated crawl saw, with a severity and the rule it relates to. None of them issues a verdict on that rule, and none of them changes anything on the site.
Features
What each check looks at
White-label client reports
One PDF per client per month, carrying your logo, your colours and their name. Nothing in it mentions us except the disclaimer.
Learn morePayment-page scripts
Every script on a page that really takes card details, inventoried and hashed, so a change in the set or in a body is something you hear about.
Learn moreCookies before consent
The crawl loads each site cold, as a first-time visitor, and reports the cookies set and the trackers fired before anyone agreed to anything.
Learn moreAccessibility (WCAG 2.2 AA)
axe-core in a real browser against WCAG 2.2 AA, plus a draft accessibility statement that names the parts only your client can answer.
Learn moreKnown plugin vulnerabilities
Plugin, theme and core versions read off a site’s own public pages, matched daily against the Wordfence Intelligence advisory feed.
Learn moreSecurity headers and TLS
Six response headers per page and one TLS handshake per host: expiry, protocol version, chain and hostname. A missing header is reported as a missing header.
Learn moreLegal pages
Privacy notice, terms, cookie policy, imprint and accessibility statement: present and loading, linked but broken, or a page with nothing in it.
Learn moreStart with one page.
Paste a client’s checkout address and see what a crawl reports. No account, no card, and the report has a link you can send to anyone.