Your website is costing you money.

Four kinds of visitor can cost you money: a customer, a search engine, a scammer and a regulator. Paste your address and we look at your site as each of them, then put a price on everything we find. No jargon, and the arithmetic is shown for every number.

This sets the starting figures. You can correct them after.

Usually under a minute. No account needed. We only make requests an ordinary visitor already makes.

Or put yourself next to a competitor.

A list of your own faults is easy to close and forget. The same list beside the business down the road is a position in a race you did not know you were in.

We check both sites the same way and price them against the same assumed business, so the two figures compare like for like. Then we separate the problems you both have, which are the industry norm, from the ones only you have, which are the ones actually costing you against them.

Compare two websites

yourpractice.co.uk against thecompetition.co.uk

They are losing £291 a month less than you.

Problems only you have
4
Problems you both have
7

An illustration of the verdict. If your site is in better shape, that is what it says instead.

The kinds of thing we find, in the words we use to say it.

Real rows from real reports, rendered by the same component that renders yours. Open one and you get the arithmetic, who fixes it, roughly how long it takes, and a message you can forward to them.

Urgent

Anyone can send email that looks like it came from you

Right now a stranger can send an email that appears to come from your address and most inboxes will deliver it. That is how fake invoices reach your customers and how staff get tricked into paying them. The protection is a single DNS record and it is free.

£17/month
›How to fix it
Who does this
wherever you bought your domain
How big a job
A settings change
Roughly how long
20 min

Send this to wherever you bought your domain

Please add a DMARC record to our domain. Start in monitoring mode so nothing breaks, then tighten it once the reports look clean.

For whoever does the work

dns
Type:  TXT
Name:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.co.uk
The technical detail

No DMARC record at _dmarc on the registrable domain.

Worth doing

Every visitor address is sent to Google before they agree to anything

Your site loads its fonts from Google servers. That means each visitor IP address goes to Google in the United States the moment the page opens, before any consent banner appears. A German court awarded damages over exactly this. Hosting the font file yourself takes ten minutes and also makes the page load faster.

£3/month
›How to fix it
Who does this
whoever built your site
How big a job
A short developer task
Roughly how long
30 min

Send this to whoever built your site

We load fonts from Google. Please download the font files, serve them from our own domain, and remove the fonts.googleapis.com link.

For whoever does the work

generic
google-webfonts-helper packages any Google font for self-hosting.
The technical detail

Stylesheet loaded from fonts.googleapis.com.

Worth doing

Your phone number cannot be tapped on a mobile

Your number is written on the page as plain text, so someone on a phone has to memorise it, leave your site, and dial it by hand. Most do not. Making it tappable is one attribute, and for a restaurant or a clinic it is the single most direct change to bookings on this list.

£46/month
›How to fix it
Who does this
whoever built your site
How big a job
One line of configuration
Roughly how long
15 min

Send this to whoever built your site

Please make our phone number a tap-to-call link everywhere it appears on the site.

For whoever does the work

html
<a href="tel:+442070000000">020 7000 0000</a>
The technical detail

Phone-like string present with no tel: link on the page.

Everything we look at, and who it is about.

Most tools in this category will not tell you what they check. Here is the whole list, in plain words, generated from the scanner itself.

Other tools split this in two and sell you a security scanner or a website audit. Your website is not two problems. It is one thing that four different people look at, and every one of them can take money off you.

169 checks in total, grouped by whose attention they are about. A free scan runs 41 of them and shows every result in full. This list is generated from the scanner itself, so it cannot say something we do not actually do.

A customer47 checks

Everything here decides whether they stay, and most of it they notice without knowing they noticed.

Looking like a real business

  • Blocklists and browser warnings
  • Browser tab icon
  • Contact information
  • Form spam protection
  • Form submission safety
  • Forwarding to any address
  • Holding page
  • Links to insecure pages
  • Opening hours
  • Physical address
  • Reviews and ratings
  • Site freshness signals
  • Tap to call
  • Text encoding declaration
  • Unfinished template text
  • Where form submissions go

The padlock and the connection

  • Certificate coverage
  • Certificate expiry
  • Certificate key size
  • Certificate lifetime
  • Certificate matches the address
  • Certificate signature strength
  • Certificate trust
  • Current encryption version
  • Insecure address redirects
  • Insecure items on a secure page
  • Old encryption versions
  • Secure connection
  • Stay-secure coverage
  • Stay-secure instruction
  • Stay-secure instruction length

Speed

  • Browser caching
  • Connection protocol
  • Image sizes
  • Mobile display
  • Page weight
  • Production build quality
  • Response compression
  • Server response speed

Usable by everyone

  • Form autofill hints
  • Form labels
  • Heading order
  • Image descriptions
  • Link descriptions
  • Page language
  • Pinch to zoom
  • Skip to content

A search engine, or an assistant answering for you12 checks

Everything here decides whether anyone arrives at all, including the growing share of people who ask an assistant instead of searching.

Being found

  • AI assistant visibility
  • Business information for search engines
  • Competing page headings
  • Crawler instructions
  • Duplicate address handling
  • How your links look when shared
  • Main page heading
  • Page auto-forwarding
  • Page title
  • Search engine access
  • Search result description
  • Site map

Somebody looking for a way in92 checks

Everything here is a door. Some of them lead to your site, and some let a stranger invoice your customers using your name.

Things that should not be public

  • API documentation
  • API schema disclosure
  • Administration login page
  • Application log file
  • Application management endpoints
  • Cloud provider credentials
  • Code that builds and runs new code
  • Code that inserts unchecked HTML
  • Configuration file backups
  • Configuration file with passwords
  • Credentials kept in the browser
  • Database export left in the open
  • Developer notes in the bundle
  • Developer notes in the page
  • Editor and deploy settings
  • Email address exposure
  • Folder browsing
  • Hidden folder index
  • How random values are generated
  • Keys in public code
  • Messages from other windows
  • Original source code
  • Package registry token
  • Private key file
  • Public cloud storage
  • Security contact
  • Server configuration page
  • Software parts list
  • Source code repository
  • Subversion metadata
  • Unencrypted addresses in code
  • Web server configuration file
  • Website backup left in the open
  • WordPress account listing
  • WordPress remote interface

Your domain and your email

  • Approved email senders
  • Approved sender method
  • Certificate issuance alerts
  • Certificate issuance control
  • Domain name server redundancy
  • Domain record signing
  • Domains resembling yours
  • Email delivery
  • Email impersonation protection
  • Email protection coverage
  • Email protection for subdomains
  • Email protection reporting
  • Email protection strength
  • Email record limits
  • Email sender record validity
  • Email sender rules
  • Email signing
  • Enforced mail encryption
  • Lookalike domains that can send email
  • Mail encryption reporting
  • Mail server redundancy
  • Verified logo in inboxes

Instructions your site gives browsers

  • Address privacy
  • Application software disclosure
  • Clickjacking defence
  • Content policy framing rule
  • Content policy source list
  • Cross-site data access
  • Device access limits
  • Embedded outside pages
  • File type enforcement
  • Links that open in a new tab
  • Script injection defence
  • Script policy strength
  • Software version disclosure
  • Which commands your server accepts
  • Which sites may read your data

Outside code your site runs

  • Add-on list and versions
  • Code we could not identify
  • Debug code in the live site
  • Known-vulnerable components
  • Outside code from dead domains
  • Outside code providers
  • Outside script verification
  • Published weaknesses in the code you load
  • Published weaknesses on your server
  • Retired browser features
  • Website software version
  • Whether your code could be read

Hosting and registration

  • Abandoned service pointers
  • Databases reachable from the internet
  • Domain renewal
  • Domain transfer lock
  • Forgotten sites on your domain
  • Outdated network services
  • Remote control services
  • The www version of your address

A regulator, or somebody's solicitor18 checks

Everything here is a rule somebody can hold you to. We cite the rule and never tell you whether you comply, because that is a lawyer's job.

Legal pages and rules

  • Accessibility statement
  • Consent before tracking
  • Cookie detail behind the banner
  • Cookie policy link
  • Privacy policy
  • Privacy policy accuracy
  • Refund and returns policy
  • Terms and conditions
  • Where form submissions go

Tracking and privacy

  • Advertising pixels
  • Cookie cross-site rules
  • Cookie lifetimes
  • Cookie protection
  • Cross-site cookie safety
  • Embedded content privacy
  • Fonts loaded from Google
  • Login cookie protection
  • Screen recording

A website does not stay fixed.

You fix what the scan found and the number goes down. Then a certificate lapses, a plugin goes stale, somebody pastes a key into the wrong file, and a competitor registers a domain one letter from yours. None of that announces itself, and none of it waits for you to think about checking.

So the number creeps back. The scan is worth running once. What is worth paying for is somebody looking every day and telling you the day it moves, which is the whole of what twenty pounds a month buys.

What watching costs

Since we started watching

£193a month less at risk

First check
£483
Today
£290

The shape of the panel a subscriber sees, with figures from a real scan of our own site. Yours uses your own numbers.

What we will not do

  • We will not tell you your site is secure. Nobody can promise that from the outside. We tell you what we checked and what we found.
  • We will not attack your website. Every check on an unverified address is a request a browser or search engine already makes.
  • We will not invent precision. Estimates come with a range and a source, and where we are guessing we say so.
  • We will not read a key back to you. If we find a password or an API key published in your code, we report where it is and nothing else.

Where the numbers come from

Every figure is built from published research and typical numbers for your kind of business, then recalculated the moment you correct them. Each one opens to show its own arithmetic, line by line, with the source next to each input.

A number nobody can check is a number nobody should believe, so every assumption we start from is published in full.

Read how we work it out

See what yours costs

This sets the starting figures. You can correct them after.