aimangatranslator.app

Scanned:

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Watch this site's security

We'll email you if its security slips: a new vulnerability, an expiring certificate, a blacklisting. No account needed.

Security alerts only. Nothing else, and no email unless something is wrong. Unsubscribe anytime.

Want more than security alerts?

Coming soon

Monitor: daily re-scans across all five axes, instant alerts on new and cert expiry, Telegram & web push, and full history.

Fix what matters first

  1. 1
    Core security headersHow to fix this →

    Add X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.

    +5
  2. 2
    HSTS (Strict-Transport-Security)How to fix this →

    Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

    +4
  3. 3
    Core Web Vitals (PageSpeed)

    Improve Core Web Vitals — see the PageSpeed Insights report for specifics.

    +5
  4. 4
    Content-Security-PolicyHow to fix this →

    Add a Content-Security-Policy to mitigate and injection.

    +2
  5. 5
    DMARC email anti-spoofing

    Add a TXT record at _dmarc (v=DMARC1; p=…) to control spoofed-email handling.

    +2

Recommendations are ranked by their impact on your score.

All checks

Security

66/ 100
  • Pass

    HTTPS & HTTP→HTTPS redirect

    HTTPS available; HTTP redirects to HTTPS

  • Pass

    TLS certificate validity

    Valid; expires in 40 days

    expires 2026-10-26 · WE1

    Good: valid certificate with 30 days or more to expiry

  • Warn

    HSTS (Strict-Transport-Security)

    No Strict-Transport-Security header

    Add `Strict-Transport-Security: max-age=31536000; includeSubDomains`.

  • Warn

    Content-Security-Policy

    No Content-Security-Policy header

    Add a Content-Security-Policy to mitigate and injection.

  • Fail

    Core security headers

    None present

    Add X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.

  • Pass

    Mixed content (HTTP on HTTPS)

    No insecure (http://) subresources

  • Pass

    SPF email anti-spoofing

    record present

    v=spf1 include:spf.efwd.registrar-servers.com ~all
  • Warn

    DMARC email anti-spoofing

    No record

    Add a TXT record at _dmarc (v=DMARC1; p=…) to control spoofed-email handling.

  • N/A

    Vulnerable front-end libraries

    No recognizable front-end library versions detected

  • N/A

    CMS known vulnerabilities

    No CMS detected

Performance

74/ 100
  • Pass

    Time to First Byte

    Fast

    62 ms

    Fast: under 800 ms · Moderate: 800–1800 ms · Slow: over 1800 ms

  • Pass

    Text compression

    Enabled

    br
  • Pass

    HTTP/2 or HTTP/3

    Modern

    HTTP/2.0 (HTTP/3 advertised)

    Modern: HTTP/2 or HTTP/3 · Outdated: HTTP/1.1 or older

  • Pass

    Cache-Control

    Present

    public, s-maxage=120, stale-while-revalidate=600
  • Warn

    Core Web Vitals (PageSpeed)

    perf 89/100, 3.2 s, 0.00 (lab)

    Good: 2.5 s or less

    Improve Core Web Vitals — see the PageSpeed Insights report for specifics.

SEO

100/ 100
  • Pass

    Page title

    50 characters

    AI Manga Translator | Translate Manga Pages Online

    Good: 10–70 characters

  • Pass

    Meta description

    136 characters

    Upload manga images or PDFs — OCR, translate, and keep speech-bubble layout. Layout-aware AI manga translation on aimangatranslator.app.

    Good: 50–160 characters

  • Pass

    Canonical URL

    Present

    https://aimangatranslator.app/
  • Pass

    robots.txt

    Present and not blocking

    https://aimangatranslator.app/robots.txt
  • Pass
  • Pass

    Single H1

    1 H1 tag(s)

    AI Manga Translator Break Language Barriers
  • Pass

    Image alt text

    15/16 images have alt (94%)

    Good: 90% or more with alt text · Poor: under 50%

  • Pass

    Structured data (JSON-LD)

    present

    Organization, WebSite, SoftwareApplication, Offer, FAQPage, Question

This page is clean. What about the rest of the site?

A clean page is a good sign and not a verdict on the site. The faults that cost the most traffic only exist between pages, so a single-page check cannot see them at all.

A full audit crawls up to 100 pages and checks

  • Indexability and crawling
  • On-page and content
  • Technical
  • Structured data and social previews
  • Links
  • Site-wide configuration

Free while in beta ($19 after launch). No domain verification — we only read pages your site already shows everyone.

Infrastructure

100/ 100
  • N/A

    CMS detection

    No CMS fingerprint detected

  • Pass

    Web server

    Identified

    cloudflare
  • Pass

    CDN detection

    Detected

    Cloudflare
  • Pass

    TLS version

    Up to date

    TLS 1.3

    Up to date: TLS 1.2 or 1.3 · Deprecated: TLS 1.0 or 1.1

  • Pass

    IPv6 (AAAA record)

    AAAA record present

    2606:4700:3032::6815:286e

Reputation

92/ 100
  • Pass

    Google Safe Browsing

    Not flagged

    checked: Google Safe Browsing
  • Pass

    Domain blacklist status

    Not on major blocklists

    checked: Spamhaus DBL, SURBL
  • Warn

    Domain age

    Registered ~1 month ago

    2026-07-23

    Good: 90 days or more since registration

    Newly registered domains carry less trust; this improves with age.

  • Pass

    Domain expiry

    Expires in 311 days

    2027-07-23

    Good: 30 days or more to expiry

Want one of these looked at properly?

This scan is broad and passive — it reads what your site shows everyone, across all five areas. A deep audit takes one of those areas and goes all the way down on your site specifically.

No email, no sign-up. Pick the one you care about.

Go deeper

This scan is passive. An attacker won't be.

The free scan reads what your site shows everyone. A Deep Audit does what an attacker does: it actively probes your verified site for what's really exposed.

This free scan (passive)

  • Security score
  • Known-CVE counts
  • Security headers
  • TLS & certificate
  • Blacklist & Safe Browsing

Deep Audit: active scan of your verified site

  • Per-CVE breakdown: IDs, severity, exploit availability, fix version
  • Exposed files (.git, .env, backups)
  • Directory listing
  • Open admin panels
  • Open ports
  • Subdomain exposure
  • Prioritized fix plan
  • Full PDF report

What we can't check without your permission

These need active probing of your site: exposed .git/.env/backups, open admin panels, open ports, forgotten subdomains. Verify your domain and we'll show you what an attacker would find.

How it works

  1. Verify your domain: a file or DNS record, about 2 minutes.
  2. We actively scan it: a few minutes; we email you when it's ready.
  3. Get your full report + PDF.

The deep scan is live and free while we're in beta. Verify your domain and run it now.

Active checks run only on a domain you've verified as yours, with your consent. We detect, never exploit. Free in beta; $39 one-time after launch, no subscription, and early adopters keep the deep scan free.

Run a free deep scan

Share this report

Request removal of this report

Recently checked

See all reports →