Scan one page, free
Paste the address of a page — a checkout is the most useful one — and we report what an automated crawl saw: the scripts it loaded, the cookies it set before anyone consented, the headers and certificate it served, and which legal pages it links to. You get a link you can send to anyone.
It is a set of observations on one date. It is not a certificate, an audit or an assessment against any standard, and nothing on the page is changed.
What a scan looks at
Six checks over one crawl
The free scan covers one page. Monitoring a whole portfolio every week is what a plan adds.
Payment-page scripts
Relevant to PCI DSS 6.4.3, 11.6.1.
Cookies and trackers before consent
Relevant to GDPR Art. 6, ePrivacy Art. 5(3).
Accessibility (WCAG 2.2 AA)
Relevant to WCAG 2.2 AA, EN 301 549.
Known plugin and theme vulnerabilities
Relevant to Wordfence Intelligence v2 advisories.
Security headers and TLS
No single standard — we report what is there and what is missing.
Legal pages
No single standard — we report what is there and what is missing.
How findings are graded
Severity, never a score
Each observation gets one of five levels, so you know what to look at first. There is no grade, no percentage and no pass or fail — a crawler cannot know those.
- critical
- Money, personal data or legal exposure is involved right now.
- high
- Should be looked at this week.
- medium
- Should be looked at this month.
- low
- A small thing to tidy when the site is next touched.
- info
- Worth knowing. Nothing to do unless it is unexpected.
Observations, not certification
A SitesProof report lists what an automated crawler saw on one web page, or a small set of pages, on one date. It is a set of observations. It is not a certificate, an audit, an assessment against any standard, or legal advice.
Read the full disclaimer