Skip to content

Website audit tool

Free Website Audit Tool

Paste a URL. SiteRune fingerprints the CMS, walks interiors from nav, sitemap, and llms.txt, and returns a brief a senior engineer can ship — not another vanity score.

Not another score. A ship file.

https://

No card. Three guest scans, then an account.

What a SiteRune website audit checks

  • Technical SEO: titles, descriptions, canonicals, H1, viewport, language, Open Graph
  • Crawlability and indexability: robots.txt, X-Robots-Tag / meta robots, sitemap presence
  • Structured data: JSON-LD parse errors and missing Organization / Article / FAQ types
  • Security configuration: HTTPS, HSTS, CSP, framing, nosniff, Referrer-Policy, Permissions-Policy, cookie flags, mixed content
  • Performance signals from this fetch: TTFB, HTML weight, compression, Cache-Control, script/image tax
  • Accessibility in the HTML: landmarks, alt text, language — not a full WCAG lab
  • CMS / framework detection from public fingerprints
  • AI crawler access (GPTBot, ClaudeBot, PerplexityBot, Google-Extended) and llms.txt quality

Example findings from a real walk

Homepage is fine. /pricing is noindex.

A leftover staging rule on an interior template. SiteRune walks linked URLs; a one-URL lab tool never sees it.

HSTS missing, CSP missing, X-Powered-By still on.

Public headers only. We draft nginx / next.config / a WordPress mu-plugin. We do not fuzz the origin.

GPTBot Disallow: / and llms.txt 404.

The AEO chapter treats that as configuration, not 'write more AI content'.

How the audit runs

  1. SSRF-safe fetch of the URL you pasted (no private or loopback targets).
  2. Follow redirects, record the chain, then fetch robots.txt, the sitemap it names, llms.txt, and security.txt.
  3. Walk same-origin links, preferring llms.txt URLs. Guest scans: 5 interiors. Signed-in Launch: up to 20.
  4. Score each walked HTML response across security, SEO, performance, AEO, CMS health, and HTML accessibility.
  5. Write a sequenced playbook plus paste-ready files. Review CSP before you enforce it.

Limits we will say out loud

  • This is not a penetration test, malware scan, or accessibility certification.
  • We do not run headless Chrome, so we do not claim Core Web Vitals or INP.
  • CMS detection is fingerprint-based. A stealth plugin will not appear.
  • We are not a rank tracker and we do not estimate traffic or backlinks.

Questions

Is the website audit free?

Three guest scans from any landing page, no card. A free Launch account keeps history and walks more interiors.

How is this different from a Lighthouse score?

Lighthouse grades one lab URL in a browser. SiteRune fetches HTML and headers, walks interiors, and attaches config files. Use both.

Will my scan be public?

Launch may list completed scans on Live briefs. You can unpublish a report. Thin or failed scans are noindex.

Scan a live URL

Same engine as the rest of SiteRune. Guest scans stay free.

https://