Every rule we check
891 documented rules across 11 modules. 462 of them affect your score; the rest are detections that report what they find without penalising you for it. Every rule has its own page explaining what it checks, the evidence it uses and how to fix it.
- Free, no signupNo account, no card
- No AI in the score986 deterministic rules
- Nothing publishedYour scans stay yours
- Answers in secondsQuick scan, no browser
SEO
107 rules · run the seo checker
- Page is not blocked by a robots meta tag
- Title tag exists
- X-Robots-Tag header does not block indexing
- Googlebot-specific noindex absent
- Title length within Google's recommended range
- Mobile viewport declared
- Canonical URL declared
- Links on this page resolve
- Exactly one H1 per page
- Character encoding declared
- Page has substantive content
- All images declare alt text
- Meta description present
- Only one canonical link
- XML sitemap found and non-empty
- Canonical URL is absolute
- H1 is not empty
- Page uses H2 subheadings
- Page links to other pages on the site
- Meta description within recommended length
- Only one title element
- Title is not too short
- No javascript: links
- Meta description is not too short
- Only one meta description
- No frameset markup
- Linked destinations are not erroring
- No empty href links
- URL is a reasonable length
- No deprecated presentational tags
- Hreflang alternates declared (detection only)
- Open Graph description present (detection only)
- Open Graph image present (detection only)
- Open Graph title present (detection only)
- About page linked (detection only)
- Article author declared (detection only)
- Article modified time declared (detection only)
- Article published time declared (detection only)
- Contact route present (detection only)
- Outbound links present (detection only)
- Favicon declared (detection only)
- H1 sits inside the main content (detection only)
- Responsive image sources declared (detection only)
- Open Graph site name declared (detection only)
- Open Graph object type declared (detection only)
- Open Graph canonical URL present (detection only)
- Privacy policy linked (detection only)
- Multiple heading levels used (detection only)
- Twitter card type declared (detection only)
- In-page anchor links present (detection only)
- Apple touch icon declared (detection only)
- Article section declared (detection only)
- Author link declared (detection only)
- Breadcrumb navigation present (detection only)
- Hreflang x-default declared (detection only)
- Page contains images (detection only)
- Page author meta declared (detection only)
- Referrer policy meta declared (detection only)
- Open Graph image alt text declared (detection only)
- Open Graph locale declared (detection only)
- Pagination links present (detection only)
- Pagination rel=next declared (detection only)
- Pagination rel=prev declared (detection only)
- Font origin preconnected (detection only)
- Product availability declared (detection only)
- Product price declared (detection only)
- Image preview size declared (detection only)
- RSS or Atom feed declared (detection only)
- Social profiles linked (detection only)
- Table of contents present (detection only)
- Terms of service linked (detection only)
- Twitter description declared (detection only)
- Twitter image declared (detection only)
- Twitter title declared (detection only)
- Page contains video (detection only)
- Web app manifest declared (detection only)
- AMP version declared (detection only)
- Content-Language meta declared (detection only)
- Copyright meta declared (detection only)
- DNS prefetch control declared (detection only)
- Conversion form present (detection only)
- Geographic meta tags declared (detection only)
- Images carry title attributes (detection only)
- Language switcher present (detection only)
- Links carry title attributes (detection only)
- Additional icon formats declared (detection only)
- iOS web app title declared (detection only)
- Application name declared (detection only)
- Format detection declared (detection only)
- Generator meta declared (detection only)
- Content rating declared (detection only)
- Browser theme colour declared (detection only)
- Nofollow usage detected (detection only)
- Noscript fallback present (detection only)
- Open Graph image height declared (detection only)
- Open Graph image width declared (detection only)
- Alternate locales declared for sharing (detection only)
- OpenSearch description declared (detection only)
- Print stylesheet declared (detection only)
- Snippet length preference declared (detection only)
- On-site search available (detection only)
- Sponsored link attribution detected (detection only)
- Twitter creator handle declared (detection only)
- Twitter image alt text declared (detection only)
- Twitter site handle declared (detection only)
- User-generated content links marked (detection only)
- Links our checker could not verify (detection only)
Answer Engine
100 rules · run the answer engine checker
- Overall question-answer coverage
- FAQPage schema present
- Heading levels descend without skipping
- Page has enough body text to be quotable
- Page has a <main> landmark
- Page opens with a substantive paragraph
- Content uses question-formatted H2s
- Enough headings to structure the answer
- Article schema present (detection only)
- Content declares an author (detection only)
- Publication date declared (detection only)
- BreadcrumbList schema present (detection only)
- Last-modified date declared (detection only)
- HowTo schema present for procedural content (detection only)
- Content uses lists (detection only)
- QAPage schema present for Q&A content (detection only)
- Content wrapped in article (detection only)
- Author biography present (detection only)
- Comparison table with headers (detection only)
- Outbound HTTPS citations present (detection only)
- Summary or key-takeaways block present (detection only)
- Content language declared (detection only)
- Enough paragraphs for depth (detection only)
- Substantive text outside images (detection only)
- Visible publication date (detection only)
- Content wrapped in <article> or <section> (detection only)
- Sources section present (detection only)
- Comparative content uses tables (detection only)
- Dates marked with machine-readable time (detection only)
- Quoted material uses blockquote (detection only)
- Bulleted items present (detection only)
- Sources marked with cite (detection only)
- Code examples marked up (detection only)
- Direct contact route present (detection only)
- Clear call to action present (detection only)
- Definitions use description lists (detection only)
- Expandable content uses details/summary (detection only)
- Disclaimer present (detection only)
- Article entity available for citation (detection only)
- BreadcrumbList entity available for citation (detection only)
- Course entity available for citation (detection only)
- Dataset entity available for citation (detection only)
- Event entity available for citation (detection only)
- FAQPage entity available for citation (detection only)
- HowTo entity available for citation (detection only)
- ItemList entity available for citation (detection only)
- JobPosting entity available for citation (detection only)
- LocalBusiness entity available for citation (detection only)
- Organization entity available for citation (detection only)
- Person entity available for citation (detection only)
- Product entity available for citation (detection only)
- QAPage entity available for citation (detection only)
- Recipe entity available for citation (detection only)
- Review entity available for citation (detection only)
- SoftwareApplication entity available for citation (detection only)
- SpeakableSpecification entity available for citation (detection only)
- VideoObject entity available for citation (detection only)
- WebSite entity available for citation (detection only)
- FAQ section detected in markup (detection only)
- Images have captions (detection only)
- Page footer landmark present (detection only)
- Glossary or definitions present (detection only)
- Page header landmark present (detection only)
- Subtitle or standfirst present (detection only)
- Images carry alt text for extraction (detection only)
- Figures pair images with context (detection only)
- Inline contextual links present (detection only)
- Methodology described (detection only)
- Microdata markup detected (detection only)
- Mixed media and structure present (detection only)
- Content split into sections (detection only)
- Enumerated items present (detection only)
- Statistics highlighted (detection only)
- Sequential content uses ordered lists (detection only)
- Pricing structure present (detection only)
- Pros and cons structure present (detection only)
- Subheadings available to phrase as questions (detection only)
- Related content links present (detection only)
- Navigation landmark aids extraction scope (detection only)
- Paragraph count supports scanning (detection only)
- Speakable schema present (detection only)
- Step markers present (detection only)
- Tables have captions (detection only)
- Testimonials or reviews present (detection only)
- Body text exceeds 1,000 characters (detection only)
- Body text exceeds 3,000 characters (detection only)
- Table-of-contents links present (detection only)
- Visible last-updated date (detection only)
- Video captions or transcript track present (detection only)
- Abbreviations expanded (detection only)
- Contact details use the address element (detection only)
- Tangential content marked with aside (detection only)
- Highlighted key passages (detection only)
- Hierarchical lists present (detection only)
- Placeholder text absent (detection only)
- RDFa markup detected (detection only)
- Reading time indicated (detection only)
- Social proof elements present (detection only)
- Key terms emphasised (detection only)
- Body text is not excessive (detection only)
AI Visibility
92 rules · run the ai visibility checker
- robots.txt does not block the whole site
- Googlebot is not blocked in robots.txt
- GPTBot is not blocked in robots.txt
- ClaudeBot is not blocked in robots.txt
- Google-Extended is not blocked in robots.txt
- OAI-SearchBot is not blocked in robots.txt
- bingbot is not blocked in robots.txt
- PerplexityBot is not blocked in robots.txt
- ChatGPT-User is not blocked in robots.txt
- Claude-User is not blocked in robots.txt
- CCBot is not blocked in robots.txt
- anthropic-ai is not blocked in robots.txt
- Applebot is not blocked in robots.txt
- meta-externalagent is not blocked in robots.txt
- PerplexityUser is not blocked in robots.txt
- robots.txt exists
- Applebot-Extended is not blocked in robots.txt
- Bytespider is not blocked in robots.txt
- AdsBot-Google is not blocked in robots.txt
- Twitterbot is not blocked in robots.txt
- facebookexternalhit is not blocked in robots.txt
- Bingbot-Extended is not blocked in robots.txt
- Bingbot-Chat is not blocked in robots.txt
- ChatGPT-Agent is not blocked in robots.txt
- Claude-SearchBot is not blocked in robots.txt
- No snippet suppression
- robots.txt references a sitemap
- Amazonbot is not blocked in robots.txt
- YouBot is not blocked in robots.txt
- Diffbot is not blocked in robots.txt
- Google-InspectionTool is not blocked in robots.txt
- Storebot-Google is not blocked in robots.txt
- Mediapartners-Google is not blocked in robots.txt
- LinkedInBot is not blocked in robots.txt
- WhatsApp is not blocked in robots.txt
- Applebot-Search is not blocked in robots.txt
- Mistralai-User is not blocked in robots.txt
- xAI-Bot is not blocked in robots.txt
- Operator is not blocked in robots.txt
- Gemini-Deep-Research is not blocked in robots.txt
- Grok is not blocked in robots.txt
- anthropic-ai-user is not blocked in robots.txt
- Links are followable
- Images remain indexable
- robots.txt declares a default group
- GoogleOther is not blocked in robots.txt
- Slackbot is not blocked in robots.txt
- Discordbot is not blocked in robots.txt
- TelegramBot is not blocked in robots.txt
- Pinterestbot is not blocked in robots.txt
- redditbot is not blocked in robots.txt
- PhindBot is not blocked in robots.txt
- AI2Bot is not blocked in robots.txt
- cohere-training-data-crawler is not blocked in robots.txt
- AhrefsBot is not blocked in robots.txt
- DeepSeekBot is not blocked in robots.txt
- NovaAct is not blocked in robots.txt
- NotebookLM is not blocked in robots.txt
- No cached-copy suppression
- Translation not blocked
- No expiry date set
- PetalBot is not blocked in robots.txt
- Neevabot is not blocked in robots.txt
- Timpibot is not blocked in robots.txt
- OmgiliBot is not blocked in robots.txt
- ImagesiftBot is not blocked in robots.txt
- FriendlyCrawler is not blocked in robots.txt
- Meltwater is not blocked in robots.txt
- Scrapy is not blocked in robots.txt
- Semrushbot is not blocked in robots.txt
- MJ12bot is not blocked in robots.txt
- DotBot is not blocked in robots.txt
- BLEXBot is not blocked in robots.txt
- Firecrawl is not blocked in robots.txt
- YandexAdditional is not blocked in robots.txt
- LinerBot is not blocked in robots.txt
- Devin is not blocked in robots.txt
- Bardbot is not blocked in robots.txt
- SidetradeIndexer is not blocked in robots.txt
- Webzio-Extended is not blocked in robots.txt
- TurnitinBot is not blocked in robots.txt
- CopyScapeBot is not blocked in robots.txt
- Grammarly is not blocked in robots.txt
- llms.txt exists
- ai.txt referenced (detection only)
- llms-full.txt referenced (detection only)
- Crawl-delay directive present (detection only)
- Host directive present (detection only)
- Snippet length controlled (detection only)
- Video preview length controlled (detection only)
- AI training opt-out declared (detection only)
- AI image training opt-out declared (detection only)
AI Agent Readiness
28 rules · run the ai agent readiness checker
- Every control has an accessible name
- Form fields are labelled
- Interactive controls are real buttons
- Navigation uses real links
- A main content region is declared
- Click handlers are not attached to generic elements
- Fields declare autocomplete tokens
- Content is structured with headings
- Content is not behind a blocking consent wall
- Menus do not require hover
- Links have real destinations
- Content is not locked inside <canvas>
- Navigation is marked as navigation
- The landing page is not gated by a CAPTCHA
- Listings are reachable without infinite scroll
- Meaning is not carried only by images
- The page has a descriptive title
- Scrolling is not hijacked
- Machine-readable actions are declared (detection only)
- Validation errors are exposed programmatically (detection only)
- Disclosure state is exposed (detection only)
- Public content is not behind a login wall (detection only)
- Required fields are marked as required (detection only)
- The site offers a search entry point (detection only)
- Page position is expressed as breadcrumbs (detection only)
- Icon-only buttons carry a label (detection only)
- Elements carry stable identifiers (detection only)
- Forms have a real submit control (detection only)
Structured Data
90 rules · run the structured data checker
- JSON-LD parses without errors
- Page declares structured data
- Organization schema present
- WebSite schema present
- @context uses https://schema.org
- Article schema present (detection only)
- BreadcrumbList schema present (detection only)
- Organization logo declared (detection only)
- sameAs profile links declared (detection only)
- Structured data declares an image (detection only)
- LocalBusiness schema present (detection only)
- Product schema present (detection only)
- WebPage schema present (detection only)
- Aggregate rating declared (detection only)
- Contact point declared (detection only)
- Event schema present (detection only)
- Offer/pricing declared (detection only)
- Person schema present (detection only)
- SearchAction schema present (detection only)
- VideoObject schema present (detection only)
- AboutPage schema detected (detection only)
- Apartment schema detected (detection only)
- AudioObject schema detected (detection only)
- BlogPosting schema detected (detection only)
- Book schema detected (detection only)
- Brand schema detected (detection only)
- CheckoutPage schema detected (detection only)
- ClaimReview schema detected (detection only)
- CollectionPage schema detected (detection only)
- ContactPage schema detected (detection only)
- Corporation schema detected (detection only)
- Course schema detected (detection only)
- CreativeWorkSeries schema detected (detection only)
- Dataset schema detected (detection only)
- Dentist schema detected (detection only)
- EducationalOrganization schema detected (detection only)
- Episode schema detected (detection only)
- Event schema detected (detection only)
- FinancialProduct schema detected (detection only)
- GeoCoordinates schema detected (detection only)
- GovernmentOrganization schema detected (detection only)
- HomeAndConstructionBusiness schema detected (detection only)
- Hotel schema detected (detection only)
- HowToStep schema detected (detection only)
- HowToSupply schema detected (detection only)
- ImageObject schema detected (detection only)
- InsuranceAgency schema detected (detection only)
- ItemList schema detected (detection only)
- JobPosting schema detected (detection only)
- LegalService schema detected (detection only)
- LoanOrCredit schema detected (detection only)
- MedicalEntity schema detected (detection only)
- Menu schema detected (detection only)
- MenuItem schema detected (detection only)
- MobileApplication schema detected (detection only)
- Movie schema detected (detection only)
- MusicRecording schema detected (detection only)
- NewsArticle schema detected (detection only)
- NGO schema detected (detection only)
- NutritionInformation schema detected (detection only)
- OpeningHoursSpecification schema detected (detection only)
- Physician schema detected (detection only)
- Place schema detected (detection only)
- PodcastEpisode schema detected (detection only)
- PostalAddress schema detected (detection only)
- ProfessionalService schema detected (detection only)
- ProfilePage schema detected (detection only)
- Quotation schema detected (detection only)
- RealEstateListing schema detected (detection only)
- Recipe schema detected (detection only)
- Restaurant schema detected (detection only)
- Review schema detected (detection only)
- ScholarlyArticle schema detected (detection only)
- SearchResultsPage schema detected (detection only)
- Season schema detected (detection only)
- Service schema detected (detection only)
- SiteNavigationElement schema detected (detection only)
- SoftwareApplication schema detected (detection only)
- SpecialAnnouncement schema detected (detection only)
- SportsTeam schema detected (detection only)
- Store schema detected (detection only)
- TechArticle schema detected (detection only)
- TouristAttraction schema detected (detection only)
- Trip schema detected (detection only)
- TVSeries schema detected (detection only)
- Vehicle schema detected (detection only)
- VideoGame schema detected (detection only)
- WebApplication schema detected (detection only)
- WPFooter schema detected (detection only)
- WPHeader schema detected (detection only)
Accessibility
205 rules · run the accessibility checker
- Body is not aria-hidden
- Images have alt text
- Form inputs have labels
- Page has a non-empty title
- Active <area> elements must have alternative text
- Elements must only use supported ARIA attributes
- aria-braille attributes must have a non-braille equivalent
- ARIA commands must have an accessible name
- ARIA attributes must be used as specified for the element's role
- Deprecated ARIA roles must not be used
- aria-hidden="true" must not be present on the document body
- ARIA hidden element must not be focusable or contain focusable elements
- ARIA input fields must have an accessible name
- ARIA meter nodes must have an accessible name
- ARIA progressbar nodes must have an accessible name
- Elements must only use permitted ARIA attributes
- Required ARIA attributes must be provided
- Certain ARIA roles must contain particular children
- Certain ARIA roles must be contained by particular parents
- aria-roledescription must be on elements with a semantic role
- ARIA roles used must conform to valid values
- ARIA tab nodes must have an accessible name
- ARIA toggle fields must have an accessible name
- ARIA tooltip nodes must have an accessible name
- ARIA attributes must conform to valid values
- ARIA attributes must conform to valid names
- <audio> elements must have a captions track
- <blink> elements are deprecated and must not be used
- Buttons must have discernible text
- Page must have means to bypass repeated blocks
- <dl> elements must only directly contain properly-ordered <dt> and <dd> groups, <script>, <template> or <div> elements
- <dt> and <dd> elements must be contained by a <dl>
- Documents must have <title> element to aid in navigation
- IDs used in ARIA and labels must be unique
- Form field must not have multiple label elements
- Frames with focusable content must not have tabindex=-1
- Frames must have a unique title attribute
- Frames must have an accessible name
- <html> element must have a lang attribute
- <html> element must have a valid value for the lang attribute
- HTML elements with lang and xml:lang must have the same base language
- Images must have alternative text
- Input buttons must have discernible text
- Image buttons must have alternative text
- Elements must have their visible text as part of their accessible name
- Form elements must have labels
- Links must be distinguishable without relying on color
- Links must have discernible text
- <ul> and <ol> must only directly contain <li>, <script> or <template> elements
- <li> elements must be contained in a <ul> or <ol>
- <marquee> elements are deprecated and must not be used
- Delayed refresh under 20 hours must not be used
- Interactive controls must not be nested
- <video> or <audio> elements must not play automatically
- <object> elements must have alternative text
- Styled <p> elements must not be used as headings
- [role="img"] elements must have alternative text
- Scrollable region must have keyboard access
- Select element must have an accessible name
- Server-side image maps must not be used
- Summary elements must have discernible text
- <svg> elements with an img role must have alternative text
- Data or header cells must not be used to give caption to a data table.
- Non-empty <td> elements in larger <table> must have an associated table header
- Table cell headers attributes must refer to other <th> elements in the same table
- Table headers in a data table must refer to data cells
- <video> elements must have captions
- Links have discernible text
- Zoom is not disabled
- Interactive elements are real controls
- Page has at least one heading
- Language attribute is non-empty
- Page has a main landmark
- No autoplaying audio or video
- No focusable content inside aria-hidden
- Exactly one H1 for document structure
- <html> declares a lang attribute
- Iframes have accessible titles
- No meta refresh redirects
- No blink or marquee elements
- role=button elements are focusable
- Select elements are labelled
- Skip-to-content link present
- No positive tabindex values
- Data tables declare header cells
- Textareas are labelled
- accesskey attribute value should be unique
- ARIA role should be appropriate for the element
- ARIA dialog and alertdialog nodes should have an accessible name
- "role=text" should have no focusable descendants
- ARIA treeitem nodes should have an accessible name
- autocomplete attribute must be used correctly
- Inline text spacing must be adjustable with custom stylesheets
- Elements must meet enhanced color contrast ratio thresholds
- Elements must meet minimum color contrast ratio thresholds
- CSS Media queries must not lock display orientation
- IDs of active elements must be unique
- id attribute value must be unique
- Headings should not be empty
- Table header text should not be empty
- Elements in the focus order should have an appropriate role
- Frames should be tested with axe-core
- Heading levels should only increase by one
- Hidden content on the page should be analyzed
- Links with the same name must have a similar purpose
- Alternative text of images should not be repeated as text
- Form elements should have a visible label
- Banner landmark should not be contained in another landmark
- Aside should not be contained in another landmark
- Contentinfo landmark should not be contained in another landmark
- Main landmark should not be contained in another landmark
- Document should not have more than one banner landmark
- Document should not have more than one contentinfo landmark
- Document should not have more than one main landmark
- Document should have one main landmark
- Landmarks should have a unique role or role/label/title (i.e. accessible name) combination
- Delayed refresh must not be used
- Users should be able to zoom and scale the text up to 500%
- Zooming and scaling must not be disabled
- Page should contain a level-one heading
- Elements marked as presentational should be consistently ignored
- All page content should be contained by landmarks
- scope attribute should be used correctly
- The skip-link target should exist and be focusable
- Elements should not have tabindex greater than zero
- Tables should not have the same summary and caption
- All touch targets must be 24px large, or leave sufficient space
- lang attribute must have a valid value
- Anchors are links or have a role
- Headings present for scanning
- Exactly one main landmark
- Placeholder is not the only label
- Buttons declare an explicit type
- Fieldsets have legends
- List items are inside list containers
- Iframe titles are non-empty
- Details elements have a summary
- Table headers declare scope
- Multiple navs are distinguishable
- Alt text avoids redundant prefixes
- No accesskey attributes
- Text is not justified
- No redundant ARIA roles
- No very small inline font sizes
- Option groups are labelled
- Title attribute used sparingly
- WCAG 1.1.1 — Non-text content (detection only)
- WCAG 1.3.1 — Info and relationships (detection only)
- WCAG 2.1.1 — Keyboard (detection only)
- WCAG 2.4.2 — Page titled (detection only)
- WCAG 3.1.1 — Language of page (detection only)
- WCAG 3.3.2 — Labels or instructions (detection only)
- WCAG 4.1.2 — Name, role, value (detection only)
- Video captions provided (detection only)
- Page has a navigation landmark (detection only)
- WCAG 1.4.10 — Reflow (detection only)
- WCAG 1.4.3 — Contrast (minimum) (detection only)
- WCAG 1.4.4 — Resize text (detection only)
- WCAG 2.2.1 — Timing adjustable (detection only)
- WCAG 2.4.1 — Bypass blocks (detection only)
- WCAG 2.4.4 — Link purpose (detection only)
- WCAG 2.4.6 — Headings and labels (detection only)
- WCAG 2.4.7 — Focus visible (detection only)
- Live regions declared (detection only)
- Autocomplete tokens supplied (detection only)
- Labels use the for attribute (detection only)
- Required fields are marked programmatically (detection only)
- Skip-link target exists (detection only)
- WCAG 1.2.2 — Captions (prerecorded) (detection only)
- WCAG 1.3.5 — Identify input purpose (detection only)
- WCAG 1.4.1 — Use of colour (detection only)
- WCAG 2.4.3 — Focus order (detection only)
- WCAG 2.5.3 — Label in name (detection only)
- WCAG 2.5.8 — Target size (minimum) (detection only)
- WCAG 3.3.1 — Error identification (detection only)
- WCAG 4.1.3 — Status messages (detection only)
- Current item indicated (detection only)
- aria-describedby in use (detection only)
- Disclosure state exposed (detection only)
- aria-labelledby in use (detection only)
- ARIA labels in use (detection only)
- Audio descriptions provided (detection only)
- Semantic input types used (detection only)
- Validation state exposed (detection only)
- Language changes marked inline (detection only)
- Links present for text review (detection only)
- Banner landmark present (detection only)
- Contentinfo landmark present (detection only)
- Dialogs use dialog semantics (detection only)
- Forms are labelled as landmarks (detection only)
- List semantics present (detection only)
- Decorative images marked correctly (detection only)
- Search region identified (detection only)
- Tabular data uses table semantics (detection only)
- Tab interfaces use tab semantics (detection only)
- WCAG 1.3.4 — Orientation (detection only)
- WCAG 1.4.12 — Text spacing (detection only)
- WCAG 2.1.4 — Character key shortcuts (detection only)
- WCAG 3.1.2 — Language of parts (detection only)
- WCAG 3.2.1 — On focus (detection only)
- WCAG 3.2.2 — On input (detection only)
- WCAG 3.3.7 — Redundant entry (detection only)
- Text direction declared where needed (detection only)
- No extreme z-index overlays (detection only)
- Complementary landmark present (detection only)
Security
53 rules · run the security checker
- Site is served over HTTPS
- Certificate chain validates against the public trust store
- Certificate covers the hostname being served
- No passwords submitted via GET
- Certificate is not close to expiry
- Connection negotiates TLS 1.2 or better
- Content-Security-Policy header present
- No mixed (insecure) content on an HTTPS page
- Negotiated cipher suite has no known weaknesses
- Forms submit over HTTPS
- CSP does not allow 'unsafe-inline' scripts
- Forms post to a relative, same-origin action
- Clickjacking protection present
- CSP does not allow 'unsafe-eval'
- Strict-Transport-Security header present
- HSTS max-age is at least one year
- No javascript: URLs
- External target=_blank links set rel=noopener
- Permissions-Policy header present
- X-Content-Type-Options is nosniff
- No credentials embedded in links
- Third-party script exposure
- HSTS covers subdomains
- Iframes are sandboxed
- External new-tab links declare rel
- Referrer-Policy header present
- CSP source keyword data: usage
- CSP source keyword 'unsafe-hashes' usage
- CSP source keyword * usage
- No plain-HTTP outbound links
- Password fields declare autocomplete
- X-Powered-By header not exposed
- Cache-Control header present (detection only)
- Cross-Origin-Opener-Policy header present (detection only)
- No inline event handler attributes (detection only)
- External scripts use Subresource Integrity (detection only)
- Content-Type declares a charset (detection only)
- Cross-Origin-Resource-Policy header present (detection only)
- Sensitive-looking hidden fields detected (detection only)
- External stylesheets use Subresource Integrity (detection only)
- CORS policy declared (detection only)
- Forms disabling autocomplete detected (detection only)
- Cross-Origin-Embedder-Policy present (detection only)
- Reporting endpoint configured (detection only)
- Cookies set on this response (detection only)
- HSTS preload flag present (detection only)
- Clear-Site-Data supported (detection only)
- Expect-CT header present (detection only)
- Network Error Logging configured (detection only)
- Origin-Agent-Cluster present (detection only)
- Pragma header present (detection only)
- DNS prefetch control declared (detection only)
- Legacy XSS filter header (detection only)
Performance
95 rules · run the performance checker
- Largest Contentful Paint within Core Web Vitals threshold
- Images declare width and height
- Cumulative Layout Shift within Core Web Vitals threshold
- Response is compressed
- First Contentful Paint within recommended threshold
- No render-blocking scripts in <head>
- Total Blocking Time within recommended threshold
- DOM size is manageable
- No document.write usage
- Script count is reasonable
- Speed Index within recommended threshold
- Stylesheet count is reasonable
- Third-party stylesheet count is low
- Iframe count is reasonable
- Image count is reasonable
- Inline script blocks are few
- Iframes are lazy-loaded
- DOM element count is moderate
- Few base64-inlined images
- Stylesheet count is tight
- Few inline style attributes
- Inline style blocks are few
- Eager loading used sparingly
- Markup nesting is not excessive
- No nested tables
- Inline classic script count
- Script count is tight
- Link count is moderate
- Tracking pixel count is moderate
- Form count is moderate
- Form control count is moderate
- No AppCache manifest
- Time to Interactive within threshold (detection only)
- All images reserve space (detection only)
- Below-the-fold images are lazy-loaded (detection only)
- Modern image formats in use (detection only)
- Critical CSS inlined (detection only)
- Deferred scripts in use (detection only)
- Critical fonts are preloaded (detection only)
- JavaScript execution time within budget (detection only)
- DOM size within budget (detection only)
- First Meaningful Paint within budget (detection only)
- Time to Interactive within budget (detection only)
- Main-thread work within budget (detection only)
- Max Potential First Input Delay within budget (detection only)
- Network round-trip time within budget (detection only)
- Server response time within budget (detection only)
- Speed Index within budget (detection only)
- Total page weight within budget (detection only)
- Autoplaying video is limited (detection only)
- Preconnect hints for critical third-party origins (detection only)
- Preload hints present (detection only)
- Async scripts in use (detection only)
- Cache max-age declared (detection only)
- DNS prefetch hints present (detection only)
- Early Hints Link header present (detection only)
- ETag header present (detection only)
- Image sizes attribute present (detection only)
- Images decode asynchronously (detection only)
- Fetch priority declared on key images (detection only)
- Last-Modified header present (detection only)
- Module preload hints present (detection only)
- ES modules in use (detection only)
- CSS @import usage review (detection only)
- Art-directed images use picture (detection only)
- Preconnect usage is restrained (detection only)
- Prefetch hints for likely next navigations (detection only)
- Speculation rules present (detection only)
- Vary header present (detection only)
- Videos declare a poster (detection only)
- Video preloading is restrained (detection only)
- Webfont loading detected (detection only)
- Client Hints requested (detection only)
- CDN Age header present (detection only)
- Alt-Svc advertises a faster protocol (detection only)
- Audio preloading is restrained (detection only)
- Immutable caching for static assets (detection only)
- stale-while-revalidate configured (detection only)
- CDN cache control declared (detection only)
- Content-Length declared (detection only)
- Animated content efficiency (Lighthouse) (detection only)
- LCP element identified (Lighthouse) (detection only)
- Layout shift sources (Lighthouse) (detection only)
- Legacy JavaScript polyfills (Lighthouse) (detection only)
- Long main-thread tasks (Lighthouse) (detection only)
- Modern image format savings (Lighthouse) (detection only)
- Offscreen image savings (Lighthouse) (detection only)
- Render-blocking resources (Lighthouse) (detection only)
- Third-party impact (Lighthouse) (detection only)
- Total blocking time (Lighthouse) (detection only)
- Prefetch usage is restrained (detection only)
- Server-Timing header present (detection only)
- Inline SVG in use (detection only)
- Timing-Allow-Origin present (detection only)
- CDN cache status exposed (detection only)
HTML
65 rules · run the html checker
- Markup parses without structural errors
- Element ids stay unique
- Head contains a title element
- Document declares a viewport
- Boolean attributes are not set to false
- Form controls declare a name
- Root element declares a language
- Document declares a character encoding
- Links and buttons are not nested
- Images declare a source
- Label for attributes are not empty
- Exactly one title element
- Element permitted content
- Element permitted occurrences
- Element permitted order
- Element permitted parent
- Element required ancestor
- Element required attributes
- Element required content
- Element name
- Close order
- Close attr
- No implicit close
- No self closing
- Void content
- Prefer tbody
- Missing doctype
- Doctype html
- No utf8 bom
- Empty title
- Long title
- No dup id
- No dup attr
- Valid id
- No missing references
- Form dup name
- Map dup name
- Map id name
- Valid for
- Attribute allowed values
- Attribute misuse
- Input attributes
- Valid autocomplete
- Deprecated
- No deprecated attr
- No conditional comment
- Script type
- Script element
- Unrecognized char ref
- No raw characters
- Meta refresh
- Anchors declare a destination
- Iframes declare a title
- Link elements declare a relationship
- Lists contain only list items
- Language attributes are not empty
- Links are not empty
- No obsolete elements
- No positive tabindex values
- Image map areas have alt text
- No deprecated presentational attributes
- Inline styles used sparingly
- Few empty elements
- Script elements omit the obsolete type attribute
- Inputs use semantic types (detection only)
CSS
29 rules · run the css checker
- Stylesheets parse without errors
- No CSS expression() usage
- No sub-legible font sizes
- Declarations use real CSS properties
- Declaration values match their property grammar
- Stylesheet respects reduced-motion preferences
- CSS features work in every major browser
- Stylesheets are not chained with @import
- Inline styles avoid !important
- Content is not bulk-hidden with inline styles
- No fixed positioning in inline styles
- Stylesheet count stays low
- Styling is not predominantly inline
- Stylesheets are not declared in the body
- Document declares its supported colour schemes
- Transitions name the properties they animate
- No escalating z-index values
- Few fixed-pixel inline font sizes
- Cache busting uses filenames rather than query strings
- Few vendor-prefixed inline properties
- Print stylesheets are scoped to print
- Critical CSS inlined in the head (detection only)
- Fonts are preloaded (detection only)
- Critical fonts are preloaded (detection only)
- Third-party style origins are preconnected (detection only)
- External stylesheets in use (detection only)
- Media attributes used on stylesheets (detection only)
- Print styles declared (detection only)
- Newly-available CSS features in use (detection only)
Trust & Scam
27 rules · run the trust & scam checker
- Sensitive forms are not submitted insecurely
- No direct executable downloads
- No secrets in link URLs
- Passwords are never submitted in a URL
- A contact route is reachable
- Forms submit over HTTPS
- No obfuscated link destinations
- Privacy policy is linked
- An about page is linked
- New-tab links are opened safely
- Page declares a canonical URL
- No artificial urgency timers
- No fabricated scarcity claims
- Machine-readable identity is declared
- A physical address is published
- Terms are linked
- Links use HTTPS
- Few interstitial overlays
- Trust badges are not decorative images
- Social profiles are linked
- Ownership is stated
- A favicon is published
- Content declares an author (detection only)
- Published email addresses are tappable (detection only)
- Little hidden inline content (detection only)
- Outbound links are present and attributable (detection only)
- Published phone numbers are tappable (detection only)