See what's broken on your website, before a hacker or a search engine does.
A free scan of your site across five axes: security, performance, SEO, infrastructure and reputation. It shows the vulnerabilities an attacker would go after and the SEO problems keeping you out of search, with plain-English fixes for both.
Free scan
No sign-up
Results in 30s
Passive checks only. We read publicly available data and never intrusively probe a website. How we scan
example.com
Example
2 security issues found
jQuery 1.8.2, 5 known
70/ 100 · overall score
Security46
Performance82
SEO71
Infrastructure88
Reputation96
An outdated library with 5 known exploits, exactly what automated attacks scan for.
What the free scan finds
What's actually wrong with your site?
Most people never really check. The free scan looks at your site the way an attacker and a search engine both would, from sensitive files left open to the SEO problems keeping you out of search, and tells you in plain words what it found and how to fix it.
A site that is looked after has fewer ways in for an attacker and picks up more of the organic traffic it has already earned. The same free scan tells you where yours stands on both.
Find the holes before an attacker does
See the exposed files, weak headers, and vulnerable libraries an attacker would exploit, and close them first.
Stay out of the next breach
Outdated software and known are how sites get defaced, ransomed, or leaked. Catch them before they're used against you.
Keep off the blacklists
A hacked or flagged website gets delisted by search engines and blocked by email providers. Spot what puts you there before it does.
Earn customer trust
A secure website is table stakes for buyers. Prove yours won't leak their data.
Show up in search
The same scan flags the SEO problems keeping your pages out of search, and the performance ones that lose visitors before the page draws.
The differentiator
Fix what matters first
We rank every finding by impact, so you start with the few that actually change your score, security holes and SEO problems alike, not a wall of 40 issues.
Exposed sensitive files (.git, backups), with domain verification
Insecure cookies, mixed content
Email spoofing ( / )
Blacklisting & Safe Browsing reputation
SEO
Whether search engines can reach your pages, read them, and show them to the right search.
The page title search engines put in the result
The description shown under it in the search snippet
Correct indexing signals (canonical, noindex)
robots.txt: what crawlers are allowed to fetch
An XML sitemap, so new pages get found
One clear main heading (H1)
Image alt text, for accessibility and image search
Structured data for rich results ()
Active checks (port scanning and probing for exposed files) run only after you verify domain ownership.
And more, on every scan
Performance
Core Web Vitals and delivery, measured via the PageSpeed Insights API.
Infrastructure
What powers the website: server, CDN, DNS, and TLS setup.
Reputation
Whether the domain is trusted, clean, and in good standing.
5
axes
32
checks per scan
Built on trusted, open data sources
Google PageSpeed Insights
Google Safe Browsing
retire.js
OSV.dev
NVD
GitHub Advisory
Beyond the free scan
Two deep audits, when the free scan finds something
The free scan reads one page. When you want the whole picture, go deep on the two things that quietly cost you traffic and trust: a full-site SEO audit, and a security deep scan of your own site. Both are free while we are in beta.
SEO audit
Every SEO problem on your site, and how to fix each one.
The free scan checks one page. The problems that actually cost you traffic live between pages: two hundred products sharing one title, a whole section nothing links to, canonical tags pointing at URLs that no longer exist. The SEO audit crawls the entire site, checks it against forty-odd technical and on-page factors, and hands back the list in the order worth fixing.
What it checks:
Whether search engines are allowed to see each page at all: noindex, robots rules, canonicals that contradict themselves
Titles, descriptions and headings, including the duplicates only a whole-site crawl can see
Speed, mobile layout and the technical basics, measured on real pages
Structured data and the link preview people get when they share you
Internal and outgoing links that lead nowhere
Site-wide settings: HTTPS, the certificate, what happens at an address that does not exist
Every finding comes with what it costs and how to fix it on your platform, in plain English, plus a PDF you can hand to whoever does the work. No domain verification: we only read what your site already shows every visitor. Free while we're in beta, $19 after launch.
Find the exposures a visitor can't see, and get the exact fix.
The free scan shows what any visitor, or any attacker, can see from the outside. The deep scan goes further, into the files and settings they can't. Once you verify the domain is yours, it actively looks for the weaknesses that quietly leak data or let people in, and for every one it finds, it gives you a precise, step-by-step fix.
What it looks for:
Sensitive files and data left publicly reachable
Internal and administrative surfaces open to the internet
Known vulnerabilities in the exact software versions you run
WordPress defaults that make an attack easier: XML-RPC, public account names, the version file
API and storage settings that hand data out: an open cross-origin policy, a published GraphQL schema, a bucket that lists its files
Server and network exposure, including forgotten subdomains and ones someone else could claim
The specifics, and the fix for each, arrive in your report, tuned to your stack. Free while we're in beta. $39 after launch, and early adopters keep it free.
Deeper than a free checker, without the enterprise price
Most checkers read a padlock and a page title and call it done. We go where the problems actually are. On security, we match the exact library and CMS versions your site runs against known (OSV.dev, NVD, GitHub Advisory) and flag what an attacker would use first. On SEO, we crawl every page for the duplicate titles, broken canonicals and noindex rules that keep you out of search. Enterprise tools go this deep too, behind a sales call and a five-figure invoice. We give you the same depth on any site, in plain English, for a price a freelancer can expense.
Example
jQuery 1.8.2, 5 known CVEs
Fix: upgrade to 3.x
Example
18 pages set to noindex
Fix: drop the rule where it doesn't belong
Deeper than a free checker, without the enterprise price
Capability
Health checkers
Enterprise scanners
CheckWeb
Real vulnerability & detection
✗no
✓yes
✓yes
Full-site SEO crawl, not just one page
✗no
✗no
✓yes
Duplicate titles, canonicals & noindex across pages
✗no
✗no
✓yes
Finds exposed files & security misconfigs
✗no
✓yes
✓yes
Plain-English findings, no jargon
✓yes
✗no
✓yes
Free scan on any website, no sign-up
varies
✗no
✓yes
Public shareable report
✗no
✗no
✓yes
Continuous monitoring (security & SEO)
✗no
✓yes
✓yes
…the depth you need on both, without the enterprise price tag or the sign-up wall.
Share your results
Every scan becomes a shareable public report
Each result gets its own clean, shareable page at chkweb.com/report/<domain> — one link that shows anyone exactly what we found.
Indexable by design
Reports are server-rendered pages that search engines and AI answer engines can read and cite.
A link you can hand to anyone
Send the report to a developer, a client or a host and they see the same findings you do, with no account and nothing to install.
One-click sharing
Share to X or LinkedIn, or copy the link. The score travels with it.
Actively scan your own verified site for what attackers exploit, then get the exact, copy-paste fix for each, tuned to your stack. Free in beta, and early adopters keep it free.
A page dropping out of search, or a title or description that broke
Watch SSL, domain & exposed files
History & API access
Agency
Coming soon
$89/mo
For teams managing many websites.
Everything in Monitor
Multiple websites
White-label reports
Team access
The free scan is passive and works on any site, and so does the SEO audit: it crawls only pages your URL already shows everyone, so it needs no verification. The security deep scan and Monitor probe your own site actively (exposed files, ports, admin panels), which takes a one-time domain verification.
Prices in USD. The free scan and both deep audits work today, and both audits are free while we're in beta. Monitoring plans arrive in a later phase; leave your email and we'll tell you the day they launch.
Transparency
How we score your site
A single number is only useful if you trust it. Our weighting is public: security carries the most, with SEO, performance, reputation and infrastructure each counted in.
Every check returns pass, warn, or fail and carries a weight. Each axis score is the weighted share of its checks; the overall score is a weighted sum of the five axes. Security is the heaviest at 35% because it is the highest risk to you if it fails, and SEO and performance are 20% each because they decide whether the site gets found and stays fast. Critical failures like a broken certificate, no HTTPS, or a blacklisted domain cap the score outright. The full methodology is published, no black box.
How each check is scored
Pass — Meets the best-practice bar for that check.
Warn — Works, but partial or below the ideal, worth improving.
Fail — Missing or actively harmful, a priority fix.
Draft weights, calibrated on real-world data and always published.
How the 100 points split across axes
Security35%
Highest risk to the owner if it fails.
Performance20%
Real impact on conversion and SEO, but rarely existential.
SEO20%
Visibility and organic traffic.
Reputation15%
Rare, but blacklisting is critical.
Infrastructure10%
Mostly informational context.
Honest by design: hard limits
Some failures are too serious to average away. A website with a broken or untrusted certificate can't score above 50. No HTTPS at all caps you at 40. A blacklisted domain is capped too. That's why our scores can be low, and why a high CheckWeb score actually means something.
Good (80-100)Needs work (50-79)Poor (0-49)
Would you trust a website that scores 42? Your visitors decide in seconds.
FAQ
Frequently asked questions
The short answers. More detail lands as we ship.
Can you scan my website for vulnerabilities?
Yes, that's the core of it. We detect known-vulnerable JavaScript libraries and CMS versions (matched to real ), missing security headers, TLS and certificate problems, exposed sensitive files, and blacklisting. Free, in plain English, no sign-up.
Is it safe? Do you attack my website?
No. The free scan is strictly passive: we read publicly available data (response headers, the returned HTML, DNS, the TLS certificate, the library versions a page loads), exactly what any browser or search crawler sees. We never brute-force, send exploit payloads, or probe hidden paths. Deeper active checks (probing for exposed files, admin panels, or open ports) run only after you verify you own the domain.
Do you scan WordPress sites?
Yes. We fingerprint WordPress and its version, then flag the known affecting that core version as a security finding (with the count and severity) alongside your security headers, TLS, and blacklist status. This covers the WordPress core (and Joomla, Drupal, TYPO3, Magento, PrestaShop, 1C-Bitrix). Plugin- and theme-level coverage is on the way.
What can I see for free vs. after verifying my domain?
Everything passive is free on any website: the security score, vulnerable libraries and CMS versions, headers, TLS, blacklists. Active, intrusive checks (exposed files like .git and backups, open admin panels, port scans) run only on a domain you've verified as your own. That deep scan is live today and free while we're in beta (a one-time $39 audit after launch); continuous Monitor is still coming.
What counts as a vulnerability?
Anything an attacker could use against you: a JavaScript library or CMS version with a known , a missing or misconfigured security header, an expired or weak TLS certificate, an exposed sensitive file, insecure cookies or mixed content, or a domain that's been blacklisted. We report the finding and how to fix it. We don't try to exploit it.
Is the website security check free?
Yes. The public website security check and the score are free, with no sign-up. The Deep Audit (the active scan of your own verified site) is live and free during beta (a one-time $39 audit after launch, no subscription). Continuous Monitor ($19/mo) is coming later.
How is the security score calculated?
Each check returns pass, warn, or fail with a weight. Axis scores are weighted shares; the overall score is a weighted sum of the five axes, weighted toward Security (35%). Critical security failures (a broken certificate, no HTTPS, a blacklisted domain) cap the score outright. The full methodology is published in How we score.
What sources do you use for vulnerabilities?
Open data only: retire.js for front-end libraries, OSV.dev for packages, and NVD plus GitHub Advisory for CMS and server software. No proprietary databases.
How long does a scan take?
Most scans finish in 15-30 seconds. Performance data comes from the PageSpeed Insights API and is cached to stay fast.
How often should I scan my website?
Scan whenever you ship changes, update a plugin, or renew a certificate. New versions bring new . Security isn't a one-time check: a new vulnerability in your stack, a leaked file, or a blacklisting can land any day. Continuous monitoring (coming soon) re-scans for you and alerts you the moment something new appears.
Do you store my data?
The product is built privacy-first and GDPR-aligned. Public reports are indexable by design; anything tied to an account stays under your control.