Skip to content
WebsiteValidator

Free · No account for your first scan · Results in about a minute

Your website is being judged by more than Google

Search engines, AI assistants, screen readers and browsers each hold your site to a different standard. This audits all of them in one pass — 986 deterministic checks across SEO, AI search, accessibility, security and performance, each one showing the rule it applied, the evidence on your page, and the public specification behind it.

Quick runs 93 high-signal checks in about 3 seconds, no browser. Full adds Core Web Vitals, the accessibility engines and a screenshot, and takes about a minute.

Try:
  • Browser-rendered
  • Deterministic
  • Explainable
  • 986 checks
  • Public standards
  • 0
    deterministic rules
  • 0
    regression assertions
  • 0
    audit modules
  • 0
    AI influence on any score

How it works

Three steps, and no guesswork in any of them

Every score on this site is arithmetic over rules that were written down before your page was seen. That is the whole difference between a report you can act on and one you have to take on faith.

  1. Enter your address

    Just the domain is enough — example.com, with or without the https. No account, no card, no crawl of your whole site.

  2. We render it like a visitor

    Your page opens in a real browser and JavaScript runs to completion, so what gets audited is the page a person actually sees — not the raw HTML your server sent. A screenshot comes back with the report as evidence of exactly what we measured.

  3. You get findings you can act on

    Up to 986 checks run against that rendered page. Each finding names the rule, quotes the evidence found on your page, cites the public specification behind it, and says what to change. Nothing is a judgement call — run it twice on an unchanged page and the score is identical.

One scan

Eleven areas, up to 986 checks

Every count below is read from the rule registry when this page is built, so it cannot drift from the product. AI visibility, answer engines and AI agents are three of the 11228 checks between them — and have a section of their own below.

  • SEO

    Whether search engines can index you at all — robots directives, canonicals, hreflang, pagination — and whether your titles, descriptions and headings give them anything to work with. It also checks the card your link turns into when someone pastes it into LinkedIn, Slack or WhatsApp.

  • WCAG 2.2

    Whether someone using a screen reader, a keyboard or larger text can actually use your site. The primary engine runs inside the real browser against your rendered page; a second, independent engine reads the same markup and reports what the first missed.

  • Schema

    Your JSON-LD parsed and expanded to real schema.org types, then checked against what each search feature actually requires — so you find out a recipe card will not appear before you wonder why it never did.

  • Headers & TLS

    The protective headers a browser looks for, graded directive by directive rather than present-or-absent: your content security policy checked source by source, HSTS with its max-age and subdomain coverage, clickjacking protection, mixed content — plus a real TLS handshake against your certificate.

  • Core Web Vitals

    Load speed and layout stability measured live in a real browser against Google's published thresholds — Largest Contentful Paint, Cumulative Layout Shift, First Contentful Paint and Total Blocking Time — and the rest of the rules cover the scripts, caching, images and fonts behind those numbers.

  • HTML

    Markup conformance against the HTML Living Standard, read from the raw response before any browser repairs it. A mis-nested tag or a duplicate id is invisible on screen and permanently wrong in the DOM.

  • CSS

    Your inline styles and up to ten linked stylesheets parsed against the W3C property definitions, then resolved against current browser support — so you learn a valid declaration is unsupported in Safari before your customers do.

  • Trust

    What a cautious buyer checks in four seconds: a contact route they can find, a privacy policy and terms, a published address, a named business — and the patterns that make an honest site read as a scam, like a countdown with nothing behind it or a trust seal that links nowhere.

  • GEO 100 · AEO 100 · Agentic 28

    Whether AI systems can reach you, quote you and operate your site. Three separate questions, three separate scores — see below.

Rules that cannot apply to your page do not run, so the number evaluated is the number relevant to you. The report names every area that ran and every one that did not.

AI visibility

Will ChatGPT, Perplexity and Google’s AI find your business?

Three different questions hide inside that one, and most sites pass the first and fail the others. 228 checks answer all three separately.

  • 100 checks

    Can they reach you?

    Every AI crawler obeys its own name in your robots.txt, and blocking one does nothing to the others.

    So each user-agent token is checked individually — GPTBot, OAI-SearchBot and ChatGPT-User for OpenAI; ClaudeBot, Claude-User and Claude-SearchBot for Claude; PerplexityBot, Google-Extended, Applebot-Extended and the rest, alongside the search and social crawlers. Your llms.txt is checked too, and your robots.txt is resolved the way a crawler resolves it, per RFC 9309 — groups, specificity and Allow overrides — so you learn what your file actually permits rather than what reading it top to bottom suggests.

    The one that catches people out: Google-Extended controls whether you can appear in Gemini answers and AI Overviews and has nothing to do with ordinary Google indexing. Allowing one is not allowing the other.

    Run this check
  • 100 checks

    Can they quote you?

    Being crawlable is not the same as being quotable.

    What makes a passage liftable and attributable: question-shaped headings, FAQ and how-to markup, semantic landmarks a machine can pick apart, a named author, and publication and modification dates. An answer engine that cannot tell where your answer starts and ends will summarise your competitor instead.

    Run this check
  • 28 checks

    Can an agent use you?

    For the software now booking, buying and filling in forms on people's behalf.

    Is there a real button an agent can find and read the label of, rather than a div that behaves like one. Are your form fields labelled and your inputs given the right autocomplete tokens. Can it get past your cookie banner. Is anything important behind a hover-only menu it will never trigger.

    A site can be perfectly crawlable and still be a dead end for an agent asked to book a table.

    Run this check

How each one actually reaches you

  • ChatGPT
    GPTBot · OAI-SearchBot · ChatGPT-User

    Three separate agents: one learns from your site, one indexes it for search, one fetches it live when somebody asks about you. Blocking the first does not block the third.

  • Claude
    ClaudeBot · Claude-User · Claude-SearchBot

    Splits crawling from retrieval the same way. A page fetched on a user's behalf is read at request time, so what it says today is what gets quoted today.

  • Gemini & AI Overviews
    Google-Extended

    The one almost everyone gets wrong. This token governs Gemini and AI Overviews only — it has no effect on ordinary Google ranking, and allowing Googlebot does not allow this.

  • Perplexity
    PerplexityBot · Perplexity-User

    Answers with citations, so being quotable matters as much as being reachable. Clear headings and a visible date decide whether you are the source it names.

Four products, four sets of rules, and no single setting that covers them. What AI visibility means, in full.

The AI Ready badge, at 90 or above. Score 90 or better on AI visibility — the 100 crawler-access checks — and you can display the AI Ready badge on your own site. Below the threshold the badge endpoint returns a refusal instead of an image. A badge that can refuse is the only kind worth displaying.

Coverage

Why this instead of the tools you already have

Most audit tools were built to answer one question well. That leaves the other questions to three more tools, four exports, and you reconciling them by hand.

Coverage by area across WebsiteValidator, Google Lighthouse and GTmetrix
AreaWebsiteValidatorLighthouseGTmetrix
SEO
107 checks
Every one linked to its rule
Partial
A small fixed set — titles, meta, crawlability
Not covered
Not its purpose
Accessibility
205 checks
Every one linked to its rule
Covered
A solid automated subset of WCAG
Partial
Inherited, not its focus
Security headers
105 checks
Every one linked to its rule
Not covered
Flags HTTPS and known-vulnerable libraries only
Not covered
Not covered
AI visibility
228 checks
Every one linked to its rule
Not covered
Predates the question
Not covered
Not covered
Structured data
120 checks
Every one linked to its rule
Not covered
Removed; Google splits this into a separate test
Not covered
Not covered
Core Web Vitals
100 checks
Every one linked to its rule
Covered
The reference implementation
Covered
Its speciality, with waterfalls and video
HTML & CSS conformance
94 checks
Every one linked to its rule
Not covered
Not covered
Not covered
Not covered
Business trust signals
27 checks
Every one linked to its rule
Not covered
Not covered
Not covered
Not covered

Lighthouse and GTmetrix are good tools that were built to answer narrower questions, and both remain the better choice for what they specialise in — this compares scope, not quality. Coverage described as of this deployment; our own counts are read from the rule registry at build time rather than typed in, so they cannot drift from what actually runs.

See it first

Read a real report before you run your own

Pick any site below and a report opens in a few seconds. These are live scans, not saved screenshots — you are seeing exactly what the engine returns. They are quick scans, so they do not use up your free full scan.

How the audit reaches its answer

  • Real browser

    Your page, actually rendered

  • Core Web Vitals

    Measured, not estimated

  • WCAG 2.2

    Live accessibility tree

  • W3C standards

    HTML and CSS conformance

  • Markup parser

    Errors browsers hide

  • TLS handshake

    Certificate and cipher

  • Baseline support

    Works in every browser

  • Durable history

    Scores over time

  • Typed end to end

    No untyped surface

  • Deterministic

    Same page, same score

Why believe the number

A score you can take apart

475 of the 986 rules can move your score. Every one of them will tell you what it checked, what it found, what it cost you and which published standard says so.

  • No language model touches a status or a score

    Every status and every point comes from a rule with a fixed weight. An optional model can rephrase an explanation into plainer English; it cannot change a finding, a severity or a number. The report names whether it ran at all.

  • Every rule cites the thing it enforces

    A WCAG success criterion, the HTML Living Standard, an internet RFC, a schema.org type or published research — named and linked on the rule's own page next to its severity, its confidence tier and its weight. If a finding looks wrong, the argument is with a published standard, not with us.

  • Confidence is declared, not implied

    A rule enforcing a specification and a rule encoding a well-supported heuristic do not carry the same weight, and pretending otherwise is how audit tools lose trust. Each rule declares its tier, and the tier is a multiplier on the points it can move.

  • The arithmetic is shown

    impact = importance × confidence — full on a fail, half on a warning, zero on a pass. Each area reports the points it cost you, and those reconcile against 100 minus your score, to the decimal shown. There is no hidden term.

  • The same page scores the same way twice

    The rules are deterministic: same page, same evidence, same status, same points. The one number that can move between two runs is the live speed measurement — Core Web Vitals are timed in a real browser and carry real variance, which is why the rules behind them are reported separately from the timings.

  • We run it on ourselves, and we do not score 100

    This site ships the security headers, canonical tags, structured data and crawler access the scanner reports on. It still loses points — our own content-security-policy rule flags an inline-script allowance we have not removed yet. A tool that scores itself perfectly is a tool that grades itself gently.

Every rule has its own page with its weight, its tier and its citation — browse all 986.

Show the result

Prove the domain is yours, then show the score

Add a DNS record or upload a small file — whichever kind of access you have — and three things unlock. Nothing here is required, and nothing is withheld from anyone who skips it.

  • A public report page anyone can check

    At websitevalidator.com/report/yourdomain.com — your overall and per-area scores, what each area measures, and when it was measured. It is a real indexable page, so a prospect looking you up can find it. Individual findings are never published: it says you scored 94 on security, not which header you are missing.

  • A live badge, in six styles

    A bar, a card, five stars, a small pill, a single-area badge or the AI Ready tick. Copy the HTML or Markdown and paste it in. It shows your current score rather than the score on the day you added it, and links back to your public report. An area badge shows that area's real number under its own name — never the overall score wearing an accessibility label.

  • The badge re-measures itself

    Claimed domains are re-scanned in the background once their score is more than a week old, whenever the scan queue is quiet — a visitor's scan is never held up behind one. Every badge and public page carries its measurement date, so a stale number reads as a stale number instead of passing for a current one.

  • A Website Quality Certificate

    Your domain, your score, the band, your weakest areas listed honestly worst-first, the date, and a link anyone can use to verify it. Downloads as a sharp 1200 × 630 image — the shape a slide, a case study or a LinkedIn post wants.

Verification exists so the badge means something: anyone can scan any address, but only the owner of a domain can publish a score for it. Run a scan to start.

What it costs

Nothing, and there is no upgrade button

Scan first, decide later. The full report is on screen before anything asks you for anything.

  • Without an account

    Free

    No email, no card, nothing to install.

    • One full scan a day
    • Unlimited quick scans, always
    • The complete report on screen — nothing blurred out
    • Every finding, its evidence and its fix preview
    • The self-contained HTML copy, the JSON export and the page capture
    • The fix plan as a file, for a coding agent

    Very busy shared networks hit a separate daily ceiling. Quick scans stay unlimited either way.

  • Signed in with Google

    Free

    One click. Still no card.

    • Three full scans a day
    • Unlimited quick scans
    • Scan history that follows your account, not your browser
    • Score trend across every scan of the same address
    • The branded PDF report
    • Share links, and badges for your own site

    Your first scan is not lost when you sign in — the scans from this browser move onto your account.

We keep a one-line record of each scan — the address, the date and the scores — because that is what draws your trend line. The report itself is held for an hour and never written to a database; after that, re-running the scan is the only way to see it again.

Or check one thing

Twenty-two checkers, each with its own page

Not every question needs a full audit. Each of these explains what it checks, answers the questions people actually ask about it, and has a box to run it on its own.

There is also a page for every one of the 986 rules — what it checks, its severity, its confidence tier and how it is weighted. Most carry a box to run just that rule against your address; the ones produced by the accessibility and markup engines run only as part of a scan. Browse the library.

Questions people ask first

Is it really free?
Yes. One full scan a day and unlimited quick scans with no account, no email and no card. Signing in with Google raises it to three full scans a day and adds history, a PDF, share links and badges. There is no paid tier to upgrade to.
What does it check?
Up to 986 deterministic rules across 11 areas: SEO, AI visibility, answer-engine readiness, AI agent readiness, accessibility, structured data, security, Core Web Vitals, HTML and CSS conformance, and trust and scam signals. Rules that cannot apply to your page do not run.
How long does a scan take?
A full scan opens your page in a real browser, measures Core Web Vitals and runs the accessibility engines, and usually finishes in about a minute. A quick scan answers in roughly three seconds without launching a browser, so it has no speed measurement and no live accessibility pass.
Does an AI model decide the score?
No. Every status and every point comes from a deterministic rule with a declared confidence tier and a citable reference. An optional local language model can rephrase an explanation into plainer English, but it cannot change a status, a severity or a score.
Which AI crawlers does it check?
100 checks cover AI crawler access, testing each user-agent token individually — GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, Claude-User, PerplexityBot, Google-Extended, Applebot-Extended and the rest, alongside the search and social crawlers — because each one is controlled separately in robots.txt and allowing one does nothing for the others. Your llms.txt is checked too.
Do you store my report?
No. The findings are held in an expiring store for one hour and are never written to a database. What is kept is a one-line record — the address, the date and the scores — because that is what draws your trend line over time.
Can I put my score on my own site?
Yes, once you have proved you control the domain with a DNS record or an uploaded file. You then get a public report page anyone can verify, a live badge in six styles that shows your current score, and a downloadable quality certificate. None of it is required to use the scanner.

Recent scans

Live

Find out in a minute, free

Up to 986 deterministic checks across 11 areas — each finding with the evidence that triggered it, the standard behind it, and a fix you can paste.

Run a free scan

No signup. No credit card. Nothing stored but the result.