Skip to content
SEO Optimizer is live, Audit on page SEO and AI-search readiness. Try it free
Sign in

Website · Security · Code

Find what's broken
before you ship.

Scanverra checks any URL for performance, SEO, accessibility and security issues, scans your code for secrets and vulnerable dependencies, and writes the fix for your stack.

No sign-up for website audits · Free plan, no card · 5 free scans a month on each advanced tool

See a sample report
example.com
Audit Scores
DesktopvsMobile
Performance
Needs Work
Desktop
0D
Mobile
0A
Speed & load time+41
SEO
Good
Desktop
0A
Mobile
0A
Search visibility
Accessibility
Good
Desktop
0A
Mobile
0A
WCAG compliance+1
Best Practices
Needs Work
Desktop
0C
Mobile
0A
Web standards+22

Agentic Browsing

AI accessibility · llms.txt · structured data · robots.txt

0A

Detects your stack and writes fixes for it: 35+ frameworks and platforms

Next.jsReactWordPressShopifyWebflowWixVue.jsAngularFramerGhostNuxt
  • Performance audits on desktop and mobile
  • @scanverra/cli on npm
  • SARIF for GitHub code scanning
  • Reports in 7 languages

Watch the 1-minute story

Meet Scanverra, your bug hunter

Watch one scan find the bugs hiding in a website, rank them, write the fix for your stack and prove it worked.

No sign-up. Results in about a minute.

Read the video transcript

Your website looks fine. But underneath, it's crawling with bugs. Meet Scanverra, the bug hunter for your website and your code. Paste your URL and the hunt begins. Speed, security, SEO and your stack, checked in about a minute. Every bug gets caught. Leaked keys, slow pages, missing tags. Your report ranks every bug by impact, so you know what to fix first. Each one comes with the fix, written for your stack. Copy it, or open a pull request. Then re-scan to verify, and watch your scores climb. Schedule scans to keep patrolling, with five scanners for your site and your code. Find what's broken before you ship. Start your first hunt free. No sign-up needed.

One scan, four points of view

See your site the way everyone else does

Most tools look from one angle. Scanverra checks what your visitors, search engines, attackers and your own code each run into.

Visitors

Is it fast and usable?

Core Web Vitals on desktop and mobile, accessibility checks, and broken links, images and console errors from a real browser.

Example findingLCP 4.8s on mobile: hero image is 2.1 MB
Website audit

Search engines and AI search

Can it be found?

Titles, canonicals, structured data, sitemaps and robots.txt, plus how ready your pages are to be quoted in AI answers.

Example finding3 pages point to the same canonical URL
SEO Optimizer

Attackers

What can be probed from outside?

Security headers, cookies, TLS, mixed content and secrets leaked in page scripts, ranked by severity.

Example findingNo Content-Security-Policy header
Security scan

Your code and AI agents

What are you about to ship?

Secrets, vulnerable dependencies, unsafe code patterns and risky AI-agent configs, scanned in your repo or locally with the CLI.

Example findingUnpinned MCP server in .cursor/mcp.json
Repo Scanner and CLI
One platform, every check

See every problem. Ship every fix.

Performance, security, SEO and code scanning in one workspace, with an AI-written fix attached to every finding.

example.com / performance
0/ 100

Performance

Fast on mobile

+41 since last scan
Largest Contentful Paint1.2s
Total Blocking Time80ms
Cumulative Layout Shift0.02
Speed Index1.9s
AI security

Three problems defining AI security

AI agents now write, run and ship your code. The repo scanner checks for the new ways that goes wrong, alongside the secrets, SAST and dependency checks you already run.

Automated AI attacks

Attackers hide instructions in files your coding agents trust: rules files, CLAUDE.md, copilot-instructions.md. Invisible Unicode, injected prompts and exfiltration commands turn the agent against your own repo, at machine speed.

  • Hidden Unicode payloads, decoded
  • Prompt injection and concealment phrasing
  • Instructions that ship secrets off the machine

Untrusted agentic development

Agents run shell commands, launch MCP servers and commit code, often with approvals switched off. One auto-approve setting or unpinned MCP package is all a poisoned prompt needs to reach a laptop or a CI runner.

  • Auto-approve, bypass and YOLO settings
  • Unpinned and vulnerable MCP servers
  • LLM output reaching eval() or a shell

Ungoverned AI applications

Few teams can list the models, providers and MCP servers their code uses. Every scan builds that inventory and checks it against a policy file you commit, so an unapproved model fails the scan instead of surprising an auditor.

  • AI bill of materials on every scan
  • Allow and block lists in .scanverra/ai-policy.json
  • Mapped to OWASP LLM and Agentic Top 10
Scan a repo for AI risks

Also runs in the CLI and on every pull request.

Specialized tools

Go deeper with dedicated scanners

Four tools for when a quick audit is not enough. A free account includes 5 scans a month on each.

example.com/security-scan
82/ 100
Security ScoreGood

0

Critical

1

High

3

Medium

2

Low

AI assessment: Missing Content-Security-Policy header exposes the site to XSS. Cookie flags and HSTS are configured correctly.

CSP missing Outdated TLS cipher Server header exposed

Security Scanner

Inspect HTTP headers, scan inline scripts for leaked secrets, detect CSRF gaps, mixed content, and missing SRI - with a 0–100 risk score and AI assessment.

HeadersSecretsCSRFCookies
example.com/browser-test
88A
Browser HealthGood

1.8s

LCP

0.02

CLS

180ms

TBT

Full page screenshot
0 console errors 2 broken links Mobile pass complete

Browser Audit

Loads your site in a real browser, checks every link, validates images, checks forms, and captures a full page-load filmstrip.

Broken LinksImagesFormsWeb Vitals
github.com/acme/storefront
76B

Fair · Repo Health

Quality Gate: FAILED

1

Secrets

4

SAST

2

Dep CVEs

SecurityQualityIaC
Hardcoded AWS secret keyconfig/aws.ts:12
SSRF via unvalidated fetch URLlib/proxy.ts:44
AI fix ready · Open PR in one click

Repo Scanner

Connect GitHub or Bitbucket and scan any repository for SAST issues, hardcoded secrets, dependency CVEs and IaC misconfigurations, with AI fixes and one-click pull requests on GitHub.

GitHubBitbucketSASTCVE Scanning
scanverra.com/seo-optimizer
88/ 100
example.com/blog/best-hiking-boots

Pass

GEO ready

Pass

E-E-A-T

Live

Search Console

SEO Optimizer

Scan any page for on-page SEO, GEO/AI-search readiness, and E-E-A-T trust signals. Optionally render JavaScript, connect Google Search Console for real ranking data, and get AI-written fixes.

GEOE-E-A-TSearch ConsoleJS Rendering
Monitor and report

Keep it fixed after you ship

Scheduled scans, score-drop alerts, history, side-by-side comparisons and client-ready reports.

Compare

Side-by-side scan comparison

See every metric change across scans in one matrix

Performance
SEO
Security
Accessibility
Explore the audit tool

Speed

Track Core Web Vitals

SEO

  • Meta tags
  • Structured data
0

issues found

Browser Audit

Crawl every link and form

AI Chat

ExplainPrioritizeFix

Ask about any finding

Health Score

0
Performance
SEO
Security

Free instant website assessment

PDF Reports

  • Executive summary
  • Scores by category
  • Prioritized fixes
  • Code snippets
PDF

Client-ready audit reports

Security

  • Headers
  • Secrets
  • Cookies

Catch risks before attackers do

Score History

Track every release

For developers

Built into your workflow

Run the same checks from your terminal, CI pipeline, editor or your own scripts.

Your code stays on your machine

The CLI downloads Scanverra's signed rules, scans locally and uploads only findings: file, line, rule and fix suggestion. File contents and secret values are never uploaded.

The Free plan includes 1 API key. Uploaded CLI scans count toward your monthly free Repo Scanner scans.

npx @scanverra/cli scan .
scanverra scan .
Scanverra CLI scan output: files scanned, score, and a severity breakdown

.github/workflows/scanverra.yml

on: [push, pull_request]
jobs:
  scanverra:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
    steps:
      - uses: actions/checkout@v4
      - uses: scanverra/scan-action@v1
        with:
          api-key: ${{ secrets.SCANVERRA_API_KEY }}
          fail-on: high

Pricing

Start free, upgrade when ready

Website audits are free and unlimited. A free account adds monthly scans on every advanced tool.

Free

$0

Forever free - no card required

  • Unlimited website audits
  • 5 free scans a month on each advanced tool
  • AI-written fixes and AI chat
  • Shareable report links
  • Score history (last 5 scans)
  • 1 API key for the CLI
Get started free

Pro

Most popular
$19/month

Billed monthly, cancel anytime

  • Everything in Free
  • Unlimited scans on every tool
  • Scheduled scans with score-drop alerts
  • Unlimited score history
  • More API keys for CI/CD
  • Support tickets
Get Pro

Frequently asked questions

A website audit is an automated analysis of a site's performance, SEO, accessibility, and security. It measures how fast the page loads, whether it ranks well in search, whether it meets accessibility standards, and whether it has security vulnerabilities - then explains what to fix.

PageSpeed Insights gives you scores and a list of issues for one page. Scanverra also detects your tech stack and writes the fix for it, checks security headers and leaked secrets, crawls with a real browser, and scans the code behind the site for secrets and vulnerable dependencies.

No. Website audits run without an account. A free account (Google, GitHub or email) saves your reports, adds score history and AI chat on your results, and unlocks the free monthly scans on the other tools. Scheduled scans are part of Pro.

Not with the CLI. It downloads Scanverra's signed rules, scans on your machine and uploads only findings (file path, line, rule and fix suggestion). File contents and secret values stay local unless you pass --include-code. The web Repo Scanner is different: it reads your repository through GitHub or Bitbucket to scan it on our servers.

Only what is needed to explain and fix the findings. For a website audit, that is the scan results for a public page: issues, metrics and the detected stack. For code, it is the findings plus, on the web Repo Scanner, the flagged code snippets (and the file being changed when you open a fix pull request). CLI uploads contain no code unless you pass --include-code.

A website audit usually takes 30 to 90 seconds, because the page is loaded in a real browser at desktop and mobile sizes. Browser audits take about a minute depending on site size. Repo scans depend on repository size, and CLI scans usually finish in seconds.

Scanverra detects 35+ frameworks including Next.js, React, Vue, Angular, Svelte, WordPress, Webflow, Wix, Shopify, WooCommerce, Ghost, Framer, and more - then tailors every fix to your specific stack.

Yes. Website audits are free and unlimited, no account needed, with a 15-minute wait before re-auditing the same site. A free account skips that wait for 5 audits a month. With a free account, each advanced tool includes free scans every month: Browser Audit 5, Security Scanner 5, Repo Scanner 5 (including CLI uploads) and SEO Optimizer 5. Pro removes the limits and adds scheduled scans with alerts.

Free to start, no card required

Ship with fewer surprises.
Start with one URL.

Run a free website audit now. Add the CLI to your pipeline when you're ready.

No sign-up for website audits · Code scans run locally with the CLI