Check your Project's _

One platform to audit SEO, Accessibility, Performance, Security, Best Practices, Headers, Cookies, CMS, Carbon Footprint, Code Quality, and Supply Chain — all in one scan.

Get Early Access

All-in-One Scanner

One scan. Every dimension.

Run up to 9 scanners simultaneously in a single pass. Get a unified score dashboard covering SEO, Accessibility, Performance, Security, and more — without configuring each tool individually.

  • TemplatesSave scan configurations and reuse them across projects
  • Report BuilderDrag & drop sections to compose custom reports
  • Cross-tool InsightsCorrelate findings across scanners for deeper analysis
92
87
95
78

Individual Scanners

16 specialized tools to audit every aspect of your web project.

SEO Scanner

Analyze meta tags, headings, structured data, Open Graph, canonical URLs, robots directives, and sitemap compliance. Get actionable recommendations to improve search engine rankings.

AI Insights

AI-powered analysis of SEO issues with prioritized recommendations and fix suggestions.

Summary

Overview dashboard with score breakdown by category (meta, content, technical).

Issues

Complete list of SEO issues found, filterable by severity and category.

Lighthouse Audits

Full Lighthouse SEO audit results with pass/fail status for each check.

Links

Internal and external link analysis — broken links, redirects, nofollow distribution.

Structured Data

Schema.org markup validation and rich snippet eligibility assessment.

Keywords Rankings

Track keyword positions across search engines. Monitor ranking changes and identify opportunities for optimization.

Trend

Historical score chart showing SEO health evolution over time.

Accessibility Scanner

WCAG 2.2 compliance audit powered by axe-core. Detect contrast issues, missing alt text, keyboard traps, ARIA misuse, and form accessibility problems with severity-ranked findings.

AI Insights

AI-generated accessibility recommendations with remediation code snippets.

Summary

Score overview with issue counts by severity (critical, serious, moderate, minor).

Violations

Detailed WCAG violation list with affected elements, impact level, and fix guidance.

Contrast Analysis

Color contrast checker for all text elements against WCAG AA/AAA thresholds.

Accessibility Tree

Visual representation of the page's accessibility tree structure.

Trend

Historical accessibility score progression across scans.

Performance Scanner

Lighthouse-powered performance analysis measuring Core Web Vitals (LCP, INP, CLS), resource optimization, render-blocking assets, and loading speed across mobile and desktop.

AI Insights

AI analysis of performance bottlenecks with prioritized optimization strategies.

Core Web Vitals

LCP, INP, and CLS metrics with pass/fail against Google's thresholds.

Metrics Breakdown

Detailed timing metrics: TTFB, FCP, SI, TTI, TBT with waterfall visualization.

Resource Budget

Total page weight analysis by resource type (JS, CSS, images, fonts).

Top Resources

Heaviest resources ranked by size and load impact on performance.

Image Optimization

Unoptimized images detection with format, compression, and sizing recommendations.

Opportunities

Lighthouse performance opportunities with estimated time savings.

Diagnostics

Advanced diagnostic information for performance debugging.

Trend

Performance score and Core Web Vitals history over time.

Best Practices Scanner

Evaluate modern web standards including HTTPS usage, console errors, deprecated APIs, image aspect ratios, doctype declaration, and charset encoding for a polished production site.

AI Insights

AI recommendations for modern web standards compliance improvements.

Summary

Overall score with issue distribution by category.

Issues

Best practices violations with severity, description, and remediation steps.

Console Errors

Browser console errors and warnings captured during page load.

Audits

Lighthouse best practices audit results with pass/fail details.

Trend

Best practices score evolution across historical scans.

UX Scanner

Analyze user experience across 44 rules in 7 categories. Detect interaction issues, layout problems, form usability gaps, navigation flaws, and readability concerns with dual-viewport scanning (desktop + mobile).

Interactions & Targets

Touch target sizing, proximity issues, fake clickable elements, hidden interactive controls, and mouse-only tooltips.

Layout & Responsive

Horizontal scroll, truncated text, out-of-viewport content, oversized modals, sticky header overlaps, and zoom breakage.

Forms

Input labels, placeholder-only labels, keyboard types, autocomplete, inline validation, error linking, and form grouping.

Navigation

Logo linking, page titles, external link indicators, navigation presence, and primary CTA visibility.

Feedback & State

Submit feedback, loading indicators, toast duration, and destructive action confirmation dialogs.

Readability

Font sizes, line width, line height, paragraph density, heading hierarchy, and centered long text detection.

Dual Viewport

Every page scanned in both desktop (1280×800) and mobile (390×844) viewports for comprehensive coverage.

Trend

UX score evolution over time with breakdown by dimension.

Headers Scanner

Audit HTTP security headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, Permissions-Policy, and more. Grade your site's header security posture from A+ to F.

AI Insights

AI analysis of header security posture with configuration recommendations.

Summary

Overall security grade (A+ to F) with quick status overview.

Score Breakdown

Individual scoring per header category (CSP, HSTS, permissions, etc.).

Quick Wins

Easy-to-implement header improvements for immediate security gains.

Headers

Detailed analysis of each HTTP security header — present, missing, or misconfigured.

TLS

TLS/SSL certificate and configuration analysis (protocol version, cipher suites).

Recommendations

Full list of recommended header values with copy-paste configuration snippets.

Trend

Header security score history showing improvement over time.

Inconsistencies

Cross-page header inconsistencies detected in crawl mode.

Cookies Scanner

Inventory all cookies set by your site. Classify them by purpose (functional, analytics, advertising), check for proper SameSite attributes, Secure flags, and GDPR/ePrivacy compliance.

AI Insights

AI analysis of cookie compliance and privacy risk assessment.

Summary

Cookie inventory overview with counts by purpose and compliance status.

Issues

Cookie compliance issues (missing SameSite, Secure flag, consent problems).

Trackers

Third-party tracking cookies identified with their purpose and data destinations.

Trend

Cookie compliance score evolution over time.

OWASP Scanner

Automated vulnerability detection based on the OWASP Top 10:2025. Scan for injection flaws, broken authentication, XSS, CSRF, and security misconfigurations in your web application.

Summary

Overall OWASP security score with issue distribution by severity and category coverage across the Top 10.

OWASP Top 10 Categories

Dedicated analysis for each OWASP category — Broken Access Control, Injection, Cryptographic Failures, and 7 more — with per-category scoring.

Issues

Detailed vulnerability findings with severity, affected URLs, OWASP category mapping, and step-by-step remediation guidance.

Passive & Active Checks

Combines passive analysis (headers, cookies, misconfigurations) with active probing (injection tests, XSS vectors, CSRF detection).

Multi-Page Crawl

Crawl entire applications to discover and test all endpoints, forms, and API routes against the OWASP Top 10 checklist.

Trend

Track your OWASP security score evolution across scans and monitor vulnerability remediation progress.

API Scanner

Test your REST and GraphQL APIs against the OWASP API Security Top 10. Analyze OpenAPI specs for design flaws and probe live endpoints for authentication bypass, rate limiting gaps, CORS misconfiguration, and excessive data exposure.

Spec Analysis

Upload your OpenAPI 3.x spec (JSON or YAML) and get instant feedback on 10 design flaw checks — missing auth, unvalidated params, sensitive data exposure, and more.

Active Probing

6 probe modules test your live API: auth bypass, rate limiting, CORS, security headers, error disclosure, and HTTP method enumeration.

OWASP API Top 10

Every finding mapped to the OWASP API Security Top 10 (2023) — from Broken Authentication to Security Misconfiguration.

Confirmed vs Potential

Findings are classified as "confirmed" (verified by active probing) or "potential" (from spec analysis). Score reflects the distinction.

Three Scan Modes

Spec-only (~30s, no DNS needed), Quick (~3-5 min, headers + CORS + rate limit), or Full (~10-15 min, all probes on all endpoints).

Trend

Track your API security score evolution across scans and monitor vulnerability remediation progress.

CMS Scanner

Automatically detect WordPress, Joomla, Drupal, Shopify, and 7+ other CMS platforms. Enumerate plugins, themes, and core versions, then cross-reference against a database of known vulnerabilities to find outdated and insecure components.

Detection Summary

Identify the CMS platform, version, and confidence level with detection signals breakdown.

Components

Enumerate plugins, themes, and core versions installed on the target site.

Issues

Security findings filterable by category — outdated components, known CVEs, misconfigurations.

Managed Platform Detection

Distinguish self-hosted from managed CMS platforms and adjust audit scope accordingly.

Trend

Track security score evolution across scans for the same target.

Network Scanner

Deep analysis of your domain's network infrastructure — DNS, SSL/TLS certificates, email security, WHOIS, open ports, SMTP configuration, and Certificate Transparency monitoring. Over 30 automated checks in a single scan.

DNS Analysis

Full record enumeration, DNSSEC validation, DANE/TLSA, nameserver diversity, consistency checks, dangling CNAMEs, and SOA freshness.

SSL/TLS Audit

Certificate chain validation, OCSP stapling, weak cipher detection (RC4, DES, NULL), protocol support (TLS 1.0–1.3), HSTS, and expiry monitoring.

Email Security

SPF, DKIM, DMARC policy analysis plus MTA-STS, SMTP TLS Reporting (TLSRPT), BIMI, and SMTP open relay detection with STARTTLS verification.

HTTP & Domain

HTTP→HTTPS redirect validation, WHOIS expiry monitoring, registrar lock status, and domain privacy checks.

Certificate Transparency

CT log monitoring via crt.sh — detect unauthorized certificates, discover subdomains, and flag suspicious issuances.

Port Scanning

Scan top 20 security-critical ports (databases, RDP, SMB, Telnet). Detect exposed services and DNSBL blacklist status.

Trend

Track network health score evolution across scans for the same target.

Security Scanner

Multi-cloud infrastructure security powered by Prowler. Agentless scanning across your cloud environments to detect misconfigurations, compliance violations, and security risks with AI-driven remediation.

Supported Clouds
AWS AWS
Azure Azure
GCP GCP
Kubernetes K8s
Oracle Cloud Oracle
Microsoft 365 M365
Cloudflare Cloudflare
OpenStack OpenStack
MongoDB Atlas Atlas
Google Workspace GWS
GitHub GitHub
Infrastructure as Code IaC

Agentless Scanning

Connects directly to cloud APIs without deploying agents. Zero-friction setup with read-only credentials.

500+ Security Checks

Comprehensive library of security controls covering IAM, networking, encryption, logging, and resource configuration.

Compliance Frameworks

Map findings to CIS Benchmarks, NIST 800-53, ISO 27001, PCI-DSS 4.0, HIPAA, GDPR, SOC2, and FedRAMP.

AI Remediation

AI-driven risk prioritization with actionable remediation steps and infrastructure-as-code fix suggestions.

Continuous Monitoring

Schedule recurring scans to detect configuration drift and new vulnerabilities as your infrastructure evolves.

Unified Multi-Cloud

Single dashboard across all providers. Compare security posture, track findings, and manage remediation from one place.

FinOps Scanner

Cloud cost optimization powered by Cloud Custodian. Analyze AWS, Azure, and GCP infrastructure to identify waste, underutilized resources, and savings opportunities with category-based policy scanning.

Supported Clouds
AWS AWS
Azure Azure
GCP GCP
Oracle Cloud Oracle
Tencent Cloud Tencent
Kubernetes K8s

Cost Optimization

Identify unused resources, idle instances, and over-provisioned compute to eliminate cloud waste.

8 Policy Categories

Unused Resources, Rightsizing, Reserved Instances, Storage, Idle Resources, Scheduling, Data Transfer, and Orphaned Resources.

Weighted FinOps Score

0-100 score calculated as weighted average of category pass rates. Findings penalize the score by severity: critical 3×, warning 2×, low 1×, info does not affect the score.

Severity by Cost Impact

Findings classified by estimated monthly savings: critical (>$100/mo), high (≥$50/mo), medium (>$10/mo), low (>$5/mo), info (≤$5/mo, no score impact).

Vault Integration

Secure credential management with encrypted storage. Reuse saved cloud credentials or enter them manually per scan.

Multi-Cloud Unified

Consistent analysis across AWS, Azure, and GCP with provider-specific policies and equivalent resource coverage.

Carbon Scanner

Measure the carbon footprint of your web pages. Calculate CO₂ emissions per page view based on data transfer, hosting energy mix, and caching efficiency. Get a sustainability grade.

AI Insights

AI-powered sustainability recommendations to reduce your site's carbon footprint.

Summary

CO₂ per page view estimate with sustainability grade and comparison benchmarks.

Resources

Resource breakdown by type showing carbon impact of each asset category.

Recommendations

Specific actions to reduce page weight, improve caching, and lower emissions.

Trend

Carbon footprint reduction progress tracked over historical scans.

Code Quality Scanner

Analyze your Git repository for code smells, complexity, duplication, dependency vulnerabilities, and outdated packages. Supports JavaScript, TypeScript, Python, and more.

AI Insights

AI code review with prioritized refactoring suggestions and security vulnerability analysis.

Supply Chain Scanner

Audit your dependency tree for known vulnerabilities (CVEs), license compliance issues, typosquatting risks, and unmaintained packages. Keep your supply chain secure.

AI Insights

AI assessment of dependency risk with upgrade prioritization and vulnerability remediation paths.

App Store Scanner

Analyze your mobile app's App Store Optimization (ASO). Audit metadata, keywords, reviews, and rankings on both Google Play and Apple App Store to maximize visibility and downloads.

ASO Score

Composite optimization score based on 6 weighted categories covering metadata quality, reviews, and keyword rankings.

Dual-Store Analysis

Side-by-side comparison between Google Play and Apple App Store with per-store scores and findings.

Review Analysis

Read and analyze user reviews — ratings, sentiment, version trends, and response coverage.

Keyword Rankings

Track keyword positions across store search results with historical delta and trend charts.

Competitive Analysis

Compare your app against competitors — rankings, ratings, review volume, and metadata completeness.

Trend

Track ASO score evolution and ranking changes over historical scans.

Mobile Security Scanner

Upload your Android APK for static security analysis. Detect hardcoded secrets, dangerous permissions, insecure network configurations, exported components, and third-party SDK risks — all without executing the app.

APK Upload

Drag & drop your APK file or select from disk. Secure upload via presigned S3 URLs with progress tracking. Supports files up to 500 MB.

Secrets Detection

Scan DEX bytecode for hardcoded API keys, tokens, and credentials using 800+ patterns from Gitleaks and secrets-patterns-db with entropy filtering.

Permissions Audit

Flag dangerous, deprecated, and overprivileged permissions. Detect SYSTEM_ALERT_WINDOW, BIND_DEVICE_ADMIN, and excessive permission requests.

Network Security

Analyze network_security_config.xml for cleartext traffic, user CA trust, missing certificate pinning, and wildcard domain configurations.

Component Security

Detect exported Activities, Services, Receivers, and ContentProviders without permission protection. Accounts for Android 12+ implicit export behavior.

SDK Analysis

Identify 90+ known third-party SDKs including aggressive ad networks, analytics trackers, and attribution services with privacy impact assessment.

Professional Reports

PDF

Client-ready PDF exports

Generate polished PDF reports from any scan result. Customize which sections to include, add your organization's branding, and share professional documents with stakeholders.

  • Custom BrandingYour logo, colors, and company name on every report
  • Section PickerChoose exactly which audit sections appear in the export
  • One-click ExportDownload instantly or save to your generated reports library

Credential Vault

Zero-knowledge security

Store cloud credentials for authenticated scans (AWS, Azure, GCP) with military-grade encryption. Your secrets are encrypted client-side before they ever leave the browser — the server never sees plaintext.

  • Envelope EncryptionAES-256-GCM with KMS-wrapped data keys, all client-side
  • Team SharingShare credentials securely across your organization without re-entering them
  • Ephemeral SecretsCredentials exist in memory for seconds during scan execution, then are permanently deleted
  • Rescan Without Re-entryStored credentials are reused for recurring and one-click rescans
Browser Encrypt
Transit Encrypted
Server Zero-knowledge

Scheduling & Automation

Weekly audit Every Monday 08:00
Active
Email report PDF to team@company.com
Active
On deploy Webhook trigger
Trigger

Automate your quality checks

Set up continuous monitoring for your web properties. Schedule recurring scans, receive reports by email, or trigger audits automatically on every deploy.

  • Cron SchedulingDaily, weekly, or custom intervals with on/off toggle
  • Email DeliveryAutomatically send PDF reports to your team or clients after each scan
  • Webhook TriggersFire a scan on deploy via CI/CD integration or API call

Dashboards & Alerting

My Dashboard
SEO Score 87
Performance Trend
Open Issues 12 critical · 34 warnings
Top Projects
Accessibility 94
SEO 87
Security 91

Custom Dashboards

Build personalized dashboards with drag-and-drop widgets. Monitor scores, trends, and issues across all your projects from a single view.

  • Drag & Drop WidgetsCompose your view with score gauges, trend charts, issue tables, and KPI cards
  • Flexible LayoutsResize and reposition widgets freely — each dashboard adapts to your workflow
  • Team ViewsCreate dedicated dashboards per team or project with role-based visibility
SEO Score < 80 → Slack #seo-alerts
Active
Security Score < 90 → Email security@team.com
Triggered
Any score −10 pts → Webhook + escalate
Active
Slack Email Teams Webhook

Smart Alerting

Define threshold rules and get notified the instant a score drops or a regression is detected. Route alerts to the right team via the right channel.

  • Threshold RulesSet per-tool score thresholds — trigger when SEO < 80 or Security < 90
  • Multi-Channel DeliveryEmail, Slack, Microsoft Teams, webhooks, or in-app notifications
  • Escalation PoliciesAuto-escalate unresolved alerts after a defined cooldown period

AI Insights

Intelligent recommendations

SherlQ's AI engine analyzes your scan results and generates actionable recommendations prioritized by real-world impact. Quick wins are highlighted upfront, with estimated effort for each fix.

  • Quick WinsHigh-impact, low-effort fixes surfaced first for immediate improvements
  • Effort EstimationEach issue includes a resolution effort score (minutes/hours) to help you plan
  • Fix SuggestionsAI-generated code snippets and step-by-step remediation guides
  • Trend AnalysisDetect regressions and predict quality drift before it happens
AI Recommendation
!
!

Other Features

Report Sharing

Share scan results via token-based links. Recipients access the full report without needing an account or login — perfect for clients and stakeholders.

Organization & Teams

Multi-tenant workspaces with custom roles, team grouping, and user management. Invite members, assign permissions, and control access across your organization.

Real-Time Notifications

Live WebSocket updates on every scan. See progress in real-time as each scanner completes, and get instant notifications when results are ready.

Crawl Mode

Scan single pages or crawl entire websites automatically via sitemap discovery. Audit hundreds of pages in one run and compare results across your site structure.

Credential Sharing

Share encrypted vault credentials with team members. Grant access without exposing plaintext — recipients use shared credentials directly in their scans.

SSO Integration

Single Sign-On with your identity provider. Authenticate via SAML or OpenID Connect for seamless enterprise access without managing separate credentials.

Ready to improve your web quality?

Get in touch to request early access to SherlQ.

Get Early Access