One platform to audit SEO, Accessibility, Performance, Security, Best Practices, Headers, Cookies, CMS, Carbon Footprint, Code Quality, and Supply Chain — all in one scan.
Run up to 9 scanners simultaneously in a single pass. Get a unified score dashboard covering SEO, Accessibility, Performance, Security, and more — without configuring each tool individually.
Templates — Save scan configurations and reuse them across projects
Report Builder — Drag & drop sections to compose custom reports
Cross-tool Insights — Correlate findings across scanners for deeper analysis
92
87
95
78
Individual Scanners
16 specialized tools to audit every aspect of your web project.
SEO Scanner
Analyze meta tags, headings, structured data, Open Graph, canonical URLs, robots directives, and sitemap compliance. Get actionable recommendations to improve search engine rankings.
AI Insights
AI-powered analysis of SEO issues with prioritized recommendations and fix suggestions.
Summary
Overview dashboard with score breakdown by category (meta, content, technical).
Issues
Complete list of SEO issues found, filterable by severity and category.
Lighthouse Audits
Full Lighthouse SEO audit results with pass/fail status for each check.
Links
Internal and external link analysis — broken links, redirects, nofollow distribution.
Structured Data
Schema.org markup validation and rich snippet eligibility assessment.
Keywords Rankings
Track keyword positions across search engines. Monitor ranking changes and identify opportunities for optimization.
Trend
Historical score chart showing SEO health evolution over time.
Accessibility Scanner
WCAG 2.2 compliance audit powered by axe-core. Detect contrast issues, missing alt text, keyboard traps, ARIA misuse, and form accessibility problems with severity-ranked findings.
AI Insights
AI-generated accessibility recommendations with remediation code snippets.
Summary
Score overview with issue counts by severity (critical, serious, moderate, minor).
Violations
Detailed WCAG violation list with affected elements, impact level, and fix guidance.
Contrast Analysis
Color contrast checker for all text elements against WCAG AA/AAA thresholds.
Accessibility Tree
Visual representation of the page's accessibility tree structure.
Trend
Historical accessibility score progression across scans.
Performance Scanner
Lighthouse-powered performance analysis measuring Core Web Vitals (LCP, INP, CLS), resource optimization, render-blocking assets, and loading speed across mobile and desktop.
AI Insights
AI analysis of performance bottlenecks with prioritized optimization strategies.
Core Web Vitals
LCP, INP, and CLS metrics with pass/fail against Google's thresholds.
Total page weight analysis by resource type (JS, CSS, images, fonts).
Top Resources
Heaviest resources ranked by size and load impact on performance.
Image Optimization
Unoptimized images detection with format, compression, and sizing recommendations.
Opportunities
Lighthouse performance opportunities with estimated time savings.
Diagnostics
Advanced diagnostic information for performance debugging.
Trend
Performance score and Core Web Vitals history over time.
Best Practices Scanner
Evaluate modern web standards including HTTPS usage, console errors, deprecated APIs, image aspect ratios, doctype declaration, and charset encoding for a polished production site.
AI Insights
AI recommendations for modern web standards compliance improvements.
Summary
Overall score with issue distribution by category.
Issues
Best practices violations with severity, description, and remediation steps.
Console Errors
Browser console errors and warnings captured during page load.
Audits
Lighthouse best practices audit results with pass/fail details.
Trend
Best practices score evolution across historical scans.
UX Scanner
Analyze user experience across 44 rules in 7 categories. Detect interaction issues, layout problems, form usability gaps, navigation flaws, and readability concerns with dual-viewport scanning (desktop + mobile).
Font sizes, line width, line height, paragraph density, heading hierarchy, and centered long text detection.
Dual Viewport
Every page scanned in both desktop (1280×800) and mobile (390×844) viewports for comprehensive coverage.
Trend
UX score evolution over time with breakdown by dimension.
Headers Scanner
Audit HTTP security headers: Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, Permissions-Policy, and more. Grade your site's header security posture from A+ to F.
AI Insights
AI analysis of header security posture with configuration recommendations.
Summary
Overall security grade (A+ to F) with quick status overview.
Score Breakdown
Individual scoring per header category (CSP, HSTS, permissions, etc.).
Quick Wins
Easy-to-implement header improvements for immediate security gains.
Headers
Detailed analysis of each HTTP security header — present, missing, or misconfigured.
TLS
TLS/SSL certificate and configuration analysis (protocol version, cipher suites).
Recommendations
Full list of recommended header values with copy-paste configuration snippets.
Trend
Header security score history showing improvement over time.
Inconsistencies
Cross-page header inconsistencies detected in crawl mode.
Cookies Scanner
Inventory all cookies set by your site. Classify them by purpose (functional, analytics, advertising), check for proper SameSite attributes, Secure flags, and GDPR/ePrivacy compliance.
AI Insights
AI analysis of cookie compliance and privacy risk assessment.
Summary
Cookie inventory overview with counts by purpose and compliance status.
Third-party tracking cookies identified with their purpose and data destinations.
Trend
Cookie compliance score evolution over time.
OWASP Scanner
Automated vulnerability detection based on the OWASP Top 10:2025. Scan for injection flaws, broken authentication, XSS, CSRF, and security misconfigurations in your web application.
Summary
Overall OWASP security score with issue distribution by severity and category coverage across the Top 10.
OWASP Top 10 Categories
Dedicated analysis for each OWASP category — Broken Access Control, Injection, Cryptographic Failures, and 7 more — with per-category scoring.
Issues
Detailed vulnerability findings with severity, affected URLs, OWASP category mapping, and step-by-step remediation guidance.
Passive & Active Checks
Combines passive analysis (headers, cookies, misconfigurations) with active probing (injection tests, XSS vectors, CSRF detection).
Multi-Page Crawl
Crawl entire applications to discover and test all endpoints, forms, and API routes against the OWASP Top 10 checklist.
Trend
Track your OWASP security score evolution across scans and monitor vulnerability remediation progress.
API Scanner
Test your REST and GraphQL APIs against the OWASP API Security Top 10. Analyze OpenAPI specs for design flaws and probe live endpoints for authentication bypass, rate limiting gaps, CORS misconfiguration, and excessive data exposure.
Spec Analysis
Upload your OpenAPI 3.x spec (JSON or YAML) and get instant feedback on 10 design flaw checks — missing auth, unvalidated params, sensitive data exposure, and more.
Active Probing
6 probe modules test your live API: auth bypass, rate limiting, CORS, security headers, error disclosure, and HTTP method enumeration.
OWASP API Top 10
Every finding mapped to the OWASP API Security Top 10 (2023) — from Broken Authentication to Security Misconfiguration.
Confirmed vs Potential
Findings are classified as "confirmed" (verified by active probing) or "potential" (from spec analysis). Score reflects the distinction.
Three Scan Modes
Spec-only (~30s, no DNS needed), Quick (~3-5 min, headers + CORS + rate limit), or Full (~10-15 min, all probes on all endpoints).
Trend
Track your API security score evolution across scans and monitor vulnerability remediation progress.
CMS Scanner
Automatically detect WordPress, Joomla, Drupal, Shopify, and 7+ other CMS platforms. Enumerate plugins, themes, and core versions, then cross-reference against a database of known vulnerabilities to find outdated and insecure components.
Detection Summary
Identify the CMS platform, version, and confidence level with detection signals breakdown.
Components
Enumerate plugins, themes, and core versions installed on the target site.
Issues
Security findings filterable by category — outdated components, known CVEs, misconfigurations.
Managed Platform Detection
Distinguish self-hosted from managed CMS platforms and adjust audit scope accordingly.
Trend
Track security score evolution across scans for the same target.
Network Scanner
Deep analysis of your domain's network infrastructure — DNS, SSL/TLS certificates, email security, WHOIS, open ports, SMTP configuration, and Certificate Transparency monitoring. Over 30 automated checks in a single scan.
DNS Analysis
Full record enumeration, DNSSEC validation, DANE/TLSA, nameserver diversity, consistency checks, dangling CNAMEs, and SOA freshness.
SSL/TLS Audit
Certificate chain validation, OCSP stapling, weak cipher detection (RC4, DES, NULL), protocol support (TLS 1.0–1.3), HSTS, and expiry monitoring.
Email Security
SPF, DKIM, DMARC policy analysis plus MTA-STS, SMTP TLS Reporting (TLSRPT), BIMI, and SMTP open relay detection with STARTTLS verification.
CT log monitoring via crt.sh — detect unauthorized certificates, discover subdomains, and flag suspicious issuances.
Port Scanning
Scan top 20 security-critical ports (databases, RDP, SMB, Telnet). Detect exposed services and DNSBL blacklist status.
Trend
Track network health score evolution across scans for the same target.
Security Scanner
Multi-cloud infrastructure security powered by Prowler. Agentless scanning across your cloud environments to detect misconfigurations, compliance violations, and security risks with AI-driven remediation.
Supported Clouds
AWS
Azure
GCP
K8s
Oracle
M365
Cloudflare
OpenStack
Atlas
GWS
GitHub
IaC
Agentless Scanning
Connects directly to cloud APIs without deploying agents. Zero-friction setup with read-only credentials.
500+ Security Checks
Comprehensive library of security controls covering IAM, networking, encryption, logging, and resource configuration.
Compliance Frameworks
Map findings to CIS Benchmarks, NIST 800-53, ISO 27001, PCI-DSS 4.0, HIPAA, GDPR, SOC2, and FedRAMP.
AI Remediation
AI-driven risk prioritization with actionable remediation steps and infrastructure-as-code fix suggestions.
Continuous Monitoring
Schedule recurring scans to detect configuration drift and new vulnerabilities as your infrastructure evolves.
Unified Multi-Cloud
Single dashboard across all providers. Compare security posture, track findings, and manage remediation from one place.
FinOps Scanner
Cloud cost optimization powered by Cloud Custodian. Analyze AWS, Azure, and GCP infrastructure to identify waste, underutilized resources, and savings opportunities with category-based policy scanning.
Supported Clouds
AWS
Azure
GCP
Oracle
Tencent
K8s
Cost Optimization
Identify unused resources, idle instances, and over-provisioned compute to eliminate cloud waste.
8 Policy Categories
Unused Resources, Rightsizing, Reserved Instances, Storage, Idle Resources, Scheduling, Data Transfer, and Orphaned Resources.
Weighted FinOps Score
0-100 score calculated as weighted average of category pass rates. Findings penalize the score by severity: critical 3×, warning 2×, low 1×, info does not affect the score.
Severity by Cost Impact
Findings classified by estimated monthly savings: critical (>$100/mo), high (≥$50/mo), medium (>$10/mo), low (>$5/mo), info (≤$5/mo, no score impact).
Vault Integration
Secure credential management with encrypted storage. Reuse saved cloud credentials or enter them manually per scan.
Multi-Cloud Unified
Consistent analysis across AWS, Azure, and GCP with provider-specific policies and equivalent resource coverage.
Carbon Scanner
Measure the carbon footprint of your web pages. Calculate CO₂ emissions per page view based on data transfer, hosting energy mix, and caching efficiency. Get a sustainability grade.
AI Insights
AI-powered sustainability recommendations to reduce your site's carbon footprint.
Summary
CO₂ per page view estimate with sustainability grade and comparison benchmarks.
Resources
Resource breakdown by type showing carbon impact of each asset category.
Recommendations
Specific actions to reduce page weight, improve caching, and lower emissions.
Trend
Carbon footprint reduction progress tracked over historical scans.
Code Quality Scanner
Analyze your Git repository for code smells, complexity, duplication, dependency vulnerabilities, and outdated packages. Supports JavaScript, TypeScript, Python, and more.
AI Insights
AI code review with prioritized refactoring suggestions and security vulnerability analysis.
Supply Chain Scanner
Audit your dependency tree for known vulnerabilities (CVEs), license compliance issues, typosquatting risks, and unmaintained packages. Keep your supply chain secure.
AI Insights
AI assessment of dependency risk with upgrade prioritization and vulnerability remediation paths.
App Store Scanner
Analyze your mobile app's App Store Optimization (ASO). Audit metadata, keywords, reviews, and rankings on both Google Play and Apple App Store to maximize visibility and downloads.
ASO Score
Composite optimization score based on 6 weighted categories covering metadata quality, reviews, and keyword rankings.
Dual-Store Analysis
Side-by-side comparison between Google Play and Apple App Store with per-store scores and findings.
Review Analysis
Read and analyze user reviews — ratings, sentiment, version trends, and response coverage.
Keyword Rankings
Track keyword positions across store search results with historical delta and trend charts.
Competitive Analysis
Compare your app against competitors — rankings, ratings, review volume, and metadata completeness.
Trend
Track ASO score evolution and ranking changes over historical scans.
Mobile Security Scanner
Upload your Android APK for static security analysis. Detect hardcoded secrets, dangerous permissions, insecure network configurations, exported components, and third-party SDK risks — all without executing the app.
APK Upload
Drag & drop your APK file or select from disk. Secure upload via presigned S3 URLs with progress tracking. Supports files up to 500 MB.
Secrets Detection
Scan DEX bytecode for hardcoded API keys, tokens, and credentials using 800+ patterns from Gitleaks and secrets-patterns-db with entropy filtering.
Permissions Audit
Flag dangerous, deprecated, and overprivileged permissions. Detect SYSTEM_ALERT_WINDOW, BIND_DEVICE_ADMIN, and excessive permission requests.
Network Security
Analyze network_security_config.xml for cleartext traffic, user CA trust, missing certificate pinning, and wildcard domain configurations.
Component Security
Detect exported Activities, Services, Receivers, and ContentProviders without permission protection. Accounts for Android 12+ implicit export behavior.
SDK Analysis
Identify 90+ known third-party SDKs including aggressive ad networks, analytics trackers, and attribution services with privacy impact assessment.
Professional Reports
PDF
Client-ready PDF exports
Generate polished PDF reports from any scan result. Customize which sections to include, add your organization's branding, and share professional documents with stakeholders.
Custom Branding — Your logo, colors, and company name on every report
Section Picker — Choose exactly which audit sections appear in the export
One-click Export — Download instantly or save to your generated reports library
Credential Vault
Zero-knowledge security
Store cloud credentials for authenticated scans (AWS, Azure, GCP) with military-grade encryption. Your secrets are encrypted client-side before they ever leave the browser — the server never sees plaintext.
Envelope Encryption — AES-256-GCM with KMS-wrapped data keys, all client-side
Team Sharing — Share credentials securely across your organization without re-entering them
Ephemeral Secrets — Credentials exist in memory for seconds during scan execution, then are permanently deleted
Rescan Without Re-entry — Stored credentials are reused for recurring and one-click rescans
BrowserEncrypt
TransitEncrypted
ServerZero-knowledge
Scheduling & Automation
Weekly auditEvery Monday 08:00
Active
Email reportPDF to team@company.com
Active
On deployWebhook trigger
Trigger
Automate your quality checks
Set up continuous monitoring for your web properties. Schedule recurring scans, receive reports by email, or trigger audits automatically on every deploy.
Cron Scheduling — Daily, weekly, or custom intervals with on/off toggle
Email Delivery — Automatically send PDF reports to your team or clients after each scan
Webhook Triggers — Fire a scan on deploy via CI/CD integration or API call
Dashboards & Alerting
My Dashboard
SEO Score87
Performance Trend
Open Issues12 critical · 34 warnings
Top Projects
Accessibility94
SEO87
Security91
Custom Dashboards
Build personalized dashboards with drag-and-drop widgets. Monitor scores, trends, and issues across all your projects from a single view.
Drag & Drop Widgets — Compose your view with score gauges, trend charts, issue tables, and KPI cards
Flexible Layouts — Resize and reposition widgets freely — each dashboard adapts to your workflow
Team Views — Create dedicated dashboards per team or project with role-based visibility
SEO Score < 80→ Slack #seo-alerts
Active
Security Score < 90→ Email security@team.com
Triggered
Any score −10 pts→ Webhook + escalate
Active
SlackEmailTeamsWebhook
Smart Alerting
Define threshold rules and get notified the instant a score drops or a regression is detected. Route alerts to the right team via the right channel.
Threshold Rules — Set per-tool score thresholds — trigger when SEO < 80 or Security < 90
Multi-Channel Delivery — Email, Slack, Microsoft Teams, webhooks, or in-app notifications
Escalation Policies — Auto-escalate unresolved alerts after a defined cooldown period
AI Insights
Intelligent recommendations
SherlQ's AI engine analyzes your scan results and generates actionable recommendations prioritized by real-world impact. Quick wins are highlighted upfront, with estimated effort for each fix.
Quick Wins — High-impact, low-effort fixes surfaced first for immediate improvements
Effort Estimation — Each issue includes a resolution effort score (minutes/hours) to help you plan
Fix Suggestions — AI-generated code snippets and step-by-step remediation guides
Trend Analysis — Detect regressions and predict quality drift before it happens
AI Recommendation
✓
✓
!
✓
!
✓
Other Features
Report Sharing
Share scan results via token-based links. Recipients access the full report without needing an account or login — perfect for clients and stakeholders.
Organization & Teams
Multi-tenant workspaces with custom roles, team grouping, and user management. Invite members, assign permissions, and control access across your organization.
Real-Time Notifications
Live WebSocket updates on every scan. See progress in real-time as each scanner completes, and get instant notifications when results are ready.
Crawl Mode
Scan single pages or crawl entire websites automatically via sitemap discovery. Audit hundreds of pages in one run and compare results across your site structure.
Credential Sharing
Share encrypted vault credentials with team members. Grant access without exposing plaintext — recipients use shared credentials directly in their scans.
SSO Integration
Single Sign-On with your identity provider. Authenticate via SAML or OpenID Connect for seamless enterprise access without managing separate credentials.