Security & SEO website scanner

See what's broken on your website, before a hacker or a search engine does.

A free scan of your site across five axes: security, performance, SEO, infrastructure and reputation. It shows the vulnerabilities an attacker would go after and the SEO problems keeping you out of search, with plain-English fixes for both.

  • Free scan
  • No sign-up
  • Results in 30s

Passive checks only. We read publicly available data and never intrusively probe a website. How we scan

example.com

Example

2 security issues found

jQuery 1.8.2, 5 known

70/ 100 · overall score
  • Security46
  • Performance82
  • SEO71
  • Infrastructure88
  • Reputation96

An outdated library with 5 known exploits, exactly what automated attacks scan for.

Why it matters

What a healthy website gets you

A site that is looked after has fewer ways in for an attacker and picks up more of the organic traffic it has already earned. The same free scan tells you where yours stands on both.

  • Find the holes before an attacker does

    See the exposed files, weak headers, and vulnerable libraries an attacker would exploit, and close them first.

  • Stay out of the next breach

    Outdated software and known are how sites get defaced, ransomed, or leaked. Catch them before they're used against you.

  • Keep off the blacklists

    A hacked or flagged website gets delisted by search engines and blocked by email providers. Spot what puts you there before it does.

  • Earn customer trust

    A secure website is table stakes for buyers. Prove yours won't leak their data.

  • Show up in search

    The same scan flags the SEO problems keeping your pages out of search, and the performance ones that lose visitors before the page draws.

The differentiator

Fix what matters first

We rank every finding by impact, so you start with the few that actually change your score, security holes and SEO problems alike, not a wall of 40 issues.

Example
71
Today
89
After fixing these 4
  1. 1Upgrade jQuery 1.8.2 → 3.x (5 known CVEs)+6
  2. 2Remove noindex from 12 pages that should rank+5
  3. 3Remove exposed .git directory+4
  4. 4Give 200 products sharing one title unique titles+3

Ranked by impact, effort goes where the risk and the lost traffic are.

Coverage

What we scan for

The two axes that decide whether your site is safe and whether it gets found, in full, plus the health context around them.

Security

The holes an attacker would find and exploit first, in the exact software versions you run.

SEO

Whether search engines can reach your pages, read them, and show them to the right search.

  • The page title search engines put in the result
  • The description shown under it in the search snippet
  • Correct indexing signals (canonical, noindex)
  • robots.txt: what crawlers are allowed to fetch
  • An XML sitemap, so new pages get found
  • One clear main heading (H1)
  • Image alt text, for accessibility and image search
  • Structured data for rich results ()

Active checks (port scanning and probing for exposed files) run only after you verify domain ownership.

And more, on every scan

Performance

Core Web Vitals and delivery, measured via the PageSpeed Insights API.

Infrastructure

What powers the website: server, CDN, DNS, and TLS setup.

Reputation

Whether the domain is trusted, clean, and in good standing.

  • 5

    axes

  • 32

    checks per scan

Built on trusted, open data sources

  • Google PageSpeed Insights
  • Google Safe Browsing
  • retire.js
  • OSV.dev
  • NVD
  • GitHub Advisory

Beyond the free scan

Two deep audits, when the free scan finds something

The free scan reads one page. When you want the whole picture, go deep on the two things that quietly cost you traffic and trust: a full-site SEO audit, and a security deep scan of your own site. Both are free while we are in beta.

SEO audit

Every SEO problem on your site, and how to fix each one.

The free scan checks one page. The problems that actually cost you traffic live between pages: two hundred products sharing one title, a whole section nothing links to, canonical tags pointing at URLs that no longer exist. The SEO audit crawls the entire site, checks it against forty-odd technical and on-page factors, and hands back the list in the order worth fixing.

What it checks:

  • Whether search engines are allowed to see each page at all: noindex, robots rules, canonicals that contradict themselves
  • Titles, descriptions and headings, including the duplicates only a whole-site crawl can see
  • Speed, mobile layout and the technical basics, measured on real pages
  • Structured data and the link preview people get when they share you
  • Internal and outgoing links that lead nowhere
  • Site-wide settings: HTTPS, the certificate, what happens at an address that does not exist

Every finding comes with what it costs and how to fix it on your platform, in plain English, plus a PDF you can hand to whoever does the work. No domain verification: we only read what your site already shows every visitor. Free while we're in beta, $19 after launch.

Or read the guides first: every SEO check, and how to fix it.

Deep scan

Find the exposures a visitor can't see, and get the exact fix.

The free scan shows what any visitor, or any attacker, can see from the outside. The deep scan goes further, into the files and settings they can't. Once you verify the domain is yours, it actively looks for the weaknesses that quietly leak data or let people in, and for every one it finds, it gives you a precise, step-by-step fix.

What it looks for:

  • Sensitive files and data left publicly reachable
  • Internal and administrative surfaces open to the internet
  • Known vulnerabilities in the exact software versions you run
  • WordPress defaults that make an attack easier: XML-RPC, public account names, the version file
  • API and storage settings that hand data out: an open cross-origin policy, a published GraphQL schema, a bucket that lists its files
  • Server and network exposure, including forgotten subdomains and ones someone else could claim

The specifics, and the fix for each, arrive in your report, tuned to your stack. Free while we're in beta. $39 after launch, and early adopters keep it free.

Run a deep scan

Where we fit

Deeper than a free checker, without the enterprise price

Most checkers read a padlock and a page title and call it done. We go where the problems actually are. On security, we match the exact library and CMS versions your site runs against known (OSV.dev, NVD, GitHub Advisory) and flag what an attacker would use first. On SEO, we crawl every page for the duplicate titles, broken canonicals and noindex rules that keep you out of search. Enterprise tools go this deep too, behind a sales call and a five-figure invoice. We give you the same depth on any site, in plain English, for a price a freelancer can expense.

Example

jQuery 1.8.2, 5 known CVEs

Fix: upgrade to 3.x

Example

18 pages set to noindex

Fix: drop the rule where it doesn't belong

Deeper than a free checker, without the enterprise price
CapabilityHealth checkersEnterprise scannersCheckWeb
Real vulnerability & detectionnoyesyes
Full-site SEO crawl, not just one pagenonoyes
Duplicate titles, canonicals & noindex across pagesnonoyes
Finds exposed files & security misconfigsnoyesyes
Plain-English findings, no jargonyesnoyes
Free scan on any website, no sign-upvariesnoyes
Public shareable reportnonoyes
Continuous monitoring (security & SEO)noyesyes

…the depth you need on both, without the enterprise price tag or the sign-up wall.

Share your results

Every scan becomes a shareable public report

Each result gets its own clean, shareable page at chkweb.com/report/<domain> — one link that shows anyone exactly what we found.

  • Indexable by design

    Reports are server-rendered pages that search engines and AI answer engines can read and cite.

  • A link you can hand to anyone

    Send the report to a developer, a client or a host and they see the same findings you do, with no account and nothing to install.

  • One-click sharing

    Share to X or LinkedIn, or copy the link. The score travels with it.

Scan my website
Examplechkweb.com/report/acme.com
Verified

Security score

Illustrative preview. Run a scan to generate your own.

Pricing

Simple, honest pricing

Start free. Both deep audits are free while we're in beta: a one-time audit after launch, or subscribe for continuous monitoring.

One-time

Free to start. Pay once for a deep audit, no subscription.

Quick scan

Available now
$0

A passive security scan whenever you need one.

  • On-demand passive scan
  • Public shareable report
  • Overall score
  • Core set of checks
Scan my website

SEO audit

Beta
$0

$19 one-time after launch. No subscription.

Crawl your whole site and fix every SEO problem, sorted by what to fix first. Any URL, no verification. Free while we're in beta.

  • Full-site crawl, up to 100 pages
  • 40+ technical and on-page checks
  • A prioritized "fix this first" list
  • A plain-English fix for each, by platform
  • Full PDF report
Run an SEO auditHow the SEO audit works

Security deep scan

Beta
$0

$39 one-time after launch. No subscription.

Actively scan your own verified site for what attackers exploit, then get the exact, copy-paste fix for each, tuned to your stack. Free in beta, and early adopters keep it free.

  • Verify your domain, then active scan
  • Sensitive files, exposed services, admin surfaces
  • Ports and subdomains
  • Full per- breakdown
  • Prioritized fix plan, worst first
  • Exact, copy-paste fixes for your stack
  • Full PDF report
Run a deep scanHow the security deep scan works

Subscription

Keep your site checked automatically.

Monitor

Coming soon
$19/mo

Continuous monitoring for security and SEO.

  • Daily re-scan
  • Alerts on new , cert expiry, blacklisting
  • A page dropping out of search, or a title or description that broke
  • Watch SSL, domain & exposed files
  • History & API access

Agency

Coming soon
$89/mo

For teams managing many websites.

  • Everything in Monitor
  • Multiple websites
  • White-label reports
  • Team access

The free scan is passive and works on any site, and so does the SEO audit: it crawls only pages your URL already shows everyone, so it needs no verification. The security deep scan and Monitor probe your own site actively (exposed files, ports, admin panels), which takes a one-time domain verification.

Prices in USD. The free scan and both deep audits work today, and both audits are free while we're in beta. Monitoring plans arrive in a later phase; leave your email and we'll tell you the day they launch.

Transparency

How we score your site

A single number is only useful if you trust it. Our weighting is public: security carries the most, with SEO, performance, reputation and infrastructure each counted in.

Every check returns pass, warn, or fail and carries a weight. Each axis score is the weighted share of its checks; the overall score is a weighted sum of the five axes. Security is the heaviest at 35% because it is the highest risk to you if it fails, and SEO and performance are 20% each because they decide whether the site gets found and stays fast. Critical failures like a broken certificate, no HTTPS, or a blacklisted domain cap the score outright. The full methodology is published, no black box.

How each check is scored

  • PassMeets the best-practice bar for that check.

  • WarnWorks, but partial or below the ideal, worth improving.

  • FailMissing or actively harmful, a priority fix.

Draft weights, calibrated on real-world data and always published.

How the 100 points split across axes

  • Security 35%

    Highest risk to the owner if it fails.

  • Performance 20%

    Real impact on conversion and SEO, but rarely existential.

  • SEO 20%

    Visibility and organic traffic.

  • Reputation 15%

    Rare, but blacklisting is critical.

  • Infrastructure 10%

    Mostly informational context.

Honest by design: hard limits

Some failures are too serious to average away. A website with a broken or untrusted certificate can't score above 50. No HTTPS at all caps you at 40. A blacklisted domain is capped too. That's why our scores can be low, and why a high CheckWeb score actually means something.

Good (80-100)Needs work (50-79)Poor (0-49)

Would you trust a website that scores 42? Your visitors decide in seconds.

FAQ

Frequently asked questions

The short answers. More detail lands as we ship.

Can you scan my website for vulnerabilities?

Yes, that's the core of it. We detect known-vulnerable JavaScript libraries and CMS versions (matched to real ), missing security headers, TLS and certificate problems, exposed sensitive files, and blacklisting. Free, in plain English, no sign-up.

Is it safe? Do you attack my website?

No. The free scan is strictly passive: we read publicly available data (response headers, the returned HTML, DNS, the TLS certificate, the library versions a page loads), exactly what any browser or search crawler sees. We never brute-force, send exploit payloads, or probe hidden paths. Deeper active checks (probing for exposed files, admin panels, or open ports) run only after you verify you own the domain.

Do you scan WordPress sites?

Yes. We fingerprint WordPress and its version, then flag the known affecting that core version as a security finding (with the count and severity) alongside your security headers, TLS, and blacklist status. This covers the WordPress core (and Joomla, Drupal, TYPO3, Magento, PrestaShop, 1C-Bitrix). Plugin- and theme-level coverage is on the way.

What can I see for free vs. after verifying my domain?

Everything passive is free on any website: the security score, vulnerable libraries and CMS versions, headers, TLS, blacklists. Active, intrusive checks (exposed files like .git and backups, open admin panels, port scans) run only on a domain you've verified as your own. That deep scan is live today and free while we're in beta (a one-time $39 audit after launch); continuous Monitor is still coming.

What counts as a vulnerability?

Anything an attacker could use against you: a JavaScript library or CMS version with a known , a missing or misconfigured security header, an expired or weak TLS certificate, an exposed sensitive file, insecure cookies or mixed content, or a domain that's been blacklisted. We report the finding and how to fix it. We don't try to exploit it.

Is the website security check free?

Yes. The public website security check and the score are free, with no sign-up. The Deep Audit (the active scan of your own verified site) is live and free during beta (a one-time $39 audit after launch, no subscription). Continuous Monitor ($19/mo) is coming later.

How is the security score calculated?

Each check returns pass, warn, or fail with a weight. Axis scores are weighted shares; the overall score is a weighted sum of the five axes, weighted toward Security (35%). Critical security failures (a broken certificate, no HTTPS, a blacklisted domain) cap the score outright. The full methodology is published in How we score.

What sources do you use for vulnerabilities?

Open data only: retire.js for front-end libraries, OSV.dev for packages, and NVD plus GitHub Advisory for CMS and server software. No proprietary databases.

How long does a scan take?

Most scans finish in 15-30 seconds. Performance data comes from the PageSpeed Insights API and is cached to stay fast.

How often should I scan my website?

Scan whenever you ship changes, update a plugin, or renew a certificate. New versions bring new . Security isn't a one-time check: a new vulnerability in your stack, a leaked file, or a blacklisting can land any day. Continuous monitoring (coming soon) re-scans for you and alerts you the moment something new appears.

Do you store my data?

The product is built privacy-first and GDPR-aligned. Public reports are indexable by design; anything tied to an account stays under your control.