Pick an area to explore the live catalogue. The same checks feed your reports.
Full monitoring library
Security · 8 checks
Included on every plan
Protect visitor trust. Every request to your site should be encrypted, hardened, and free of mixed content.
SSL certificateValidates your certificate chain, expiry window, and protocol strength.
HTTPS redirectConfirms all HTTP traffic redirects to HTTPS with no mixed chains.
Security headersTests for X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.
Cookie security flagsChecks whether session and auth cookies use Secure, HttpOnly, and SameSite protections.
Mixed contentDetects insecure resources loaded over HTTP on an HTTPS page.
Content Security PolicyChecks for a CSP header or meta tag that limits script injection vectors.
HSTSVerifies Strict-Transport-Security is present with a sensible max-age and includeSubDomains.
Security.txtChecks for a current RFC 9116 vulnerability-reporting route at the standard well-known URL.
Meta descriptionLength, uniqueness, and keyword relevance of your meta description tag.
Title tagValidates presence, length, and distinctiveness of your page title.
H1 tagChecks you have exactly one H1 and it aligns with the page topic.
Canonical tagConfirms a self-referencing canonical exists to prevent duplicate-content issues.
Structured dataValidates JSON-LD schema markup for rich snippets in search results.
SitemapVerifies your XML sitemap exists, parses correctly, and is referenced in robots.txt.
Twitter cardsChecks for twitter:card, twitter:title, and twitter:image meta tags.
HreflangValidates international targeting tags for multi-language sites.
Meta robotsEnsures no accidental noindex or nofollow directives are blocking crawlers.
Heading structureChecks heading hierarchy (H1 to H6) for logical order and SEO best practice.
Internal linksScans for broken internal links, orphan pages, and redirect chains.
Content policy riskFlags thin, overly templated, or link-heavy pages that look risky under modern search spam policies.
Indexability conflictsDetects contradictions between canonical, robots meta, and sitemap signals.
Page load timeMeasures time-to-interactive from a real browser rendering pass.
Full page load estimateEstimates total resource weight and load waterfall for the complete page.
CompressionChecks modern text compression is enabled for HTML, CSS, JS, JSON, and similar responses.
Image optimisationValidates format (WebP/AVIF), sizing, lazy-loading, and responsive srcset usage.
Image payload budgetFlags pages where total image weight exceeds performance budgets.
CachingValidates Cache-Control headers and asset fingerprinting for repeat visits.
MinificationDetects unminified CSS and JavaScript that inflates page weight.
Server response timeMeasures TTFB and flags slow server responses before they cascade.
Core Web VitalsReal CrUX data for LCP, INP, and CLS - the metrics Google uses for ranking.
Render-blocking budgetIdentifies scripts and stylesheets that block first paint.
Image alt textEnsures every meaningful image has descriptive alternative text.
Colour contrastValidates foreground/background contrast ratios meet WCAG AA thresholds.
ARIA labelsChecks interactive elements have proper ARIA attributes for screen readers.
Form labelsEnsures every input, select, and textarea has an associated label.
Landmark rolesVerifies semantic landmarks (nav, main, footer) for assistive navigation.
Skip linksChecks for a skip-to-content link so keyboard users can bypass navigation.
Mobile text readabilityValidates font sizes and line heights are legible on small screens.
Mobile tap targetsEnsures buttons and links are large enough and spaced for touch input.
AI Visibility SignalsCross-checks page-level AI opt-outs, llms.txt, and robots rules so your signals do not contradict each other.
Content SignalsReads Content-Signal directives in robots.txt for AI training, search, and AI input preferences.
Markdown NegotiationTests whether pages can return a markdown or plain-text variant when agents explicitly request one.
Agent Link HeadersChecks Link headers for agent-relevant discovery targets such as API catalogs or service descriptions.
Web Bot AuthVerifies the well-known signed key directory used by friendly bots and agents to authenticate their requests.
Agent Protocol DiscoveryLooks for public MCP, Agent Skills, A2A, and API Catalog discovery documents.
OAuth Resource DiscoveryChecks for OAuth and OpenID metadata so agents can discover protected-resource auth flows cleanly.
AI Bot Access ParityCompares bot responses so AI crawlers receive the same indexable page signals as standard search bots.
LLMs.txt QualityChecks whether your llms.txt exists, is parseable, and includes useful machine-readable guidance.
AI Crawler PolicyValidates explicit robots directives for common AI crawlers to avoid accidental allow/deny ambiguity.
AI Snippet Control SafetyFlags conflicting snippet directives that reduce reliable AI and search snippets.
AI Citation ReadinessAssesses canonical and structured-data citation signals so answers can attribute your domain correctly.
AI JS Dependency RatioEstimates how JS-heavy your page is versus extractable HTML to highlight crawler-readability risk.
AI Token BudgetMeasures whether pages have enough structured text for reliable retrieval and summarization.
AI ChunkabilityChecks heading and section structure so long pages split into clean retrieval chunks.
Domain expiryAlerts weeks before your domain registration lapses.
Nameserver changesDetects unexpected nameserver switches that could signal hijacking.
DNS A record driftMonitors your A/AAAA records for silent IP changes.
Email trust (SPF/DKIM/DMARC)Validates email authentication records to prevent spoofing.
CMS fingerprintIdentifies your CMS and flags known security patterns for that platform.
Robots.txtValidates syntax, crawl directives, and sitemap references.
Redirect chain hygieneChecks that canonical redirects resolve quickly without multi-hop chains or loops.
404 response handlingTests missing URLs so broken paths return a real 404 instead of a soft success page.
Analytics instrumentationConfirms analytics is present in a controlled, recognizable way so visits and conversions are measurable.
Viewport metaConfirms a mobile viewport meta tag exists with correct settings.
FaviconChecks for a valid favicon in multiple formats for browser tabs and bookmarks.
DoctypeEnsures a valid HTML5 doctype for standards-mode rendering.
CharsetValidates UTF-8 character encoding is properly declared.
Language attributeChecks the HTML lang attribute for assistive technology and search engines.
Browser runtime healthCatches uncaught JavaScript errors and failed first-party assets during a real rendered load.
Mobile viewport widthVerifies content fits within the viewport without horizontal scrolling.
Open GraphValidates og:title, og:description, og:image, and og:url for rich social previews on Facebook, LinkedIn, and others.
Social linksDetects social profile links and validates they're accessible and properly structured.
Cookie consent bannerDetects a consent interface and validates it meets GDPR, PECR, and CCPA requirements.
Pre-consent trackingChecks whether trackers fire before the visitor grants consent - a common GDPR violation.
Post-reject trackingVerifies that trackers stop after consent is declined or withdrawn.
Privacy policy disclosureConfirms a privacy policy is linked, accessible, and mentions key regulation frameworks.
Disclosure reconciliationCross-checks disclosed data practices against actual trackers found on the page.
California opt-outValidates CCPA “Do Not Sell” link presence and Global Privacy Control signal handling.
Sensitive tracker riskFlags high-risk trackers that may process sensitive data categories without explicit consent.
Compliance guidance only - not a substitute for professional legal advice.
Uptime and incidents
See the outage. See the recovery.
Scavo confirms a failed probe before alerting you, then checks the recovery before closing the incident.
Hourly on SoloFor sites where a slower cadence is enough.
Flexible (1 min to 1 hr) on TeamFor important sites and faster detection.
Recovery verificationScavo checks the site is genuinely back before closing an incident.
yoursite.com
Last checked 24s ago
30-day uptime99.98%
Response time148ms
Open incidents0
Recovery confirmed08:42 · 2 successful checks after a 3m 14s incident
Closed
Weekly website brief
yoursite.com · Monday 09:12
Two things changed. One can wait.
Your site stayed online. This week's report found one consent change worth reviewing and one lower-priority crawler signal.
1
Review consent behaviourMedium effort · visitor analytics may be affected
77 checks passed Domain renewal confirmed
Open the evidence
A report made for Monday morning
Read the important bit. Leave the detail for later.
Changes come first, healthy checks stay quiet, and the technical evidence is there when your web team needs it.
Weekly or monthly delivery
Combined agency digest or one email per site
Fix guidance, likely impact and effort
Historical reports for before-and-after checks
When something changes
Tell the right people and keep the trail.
Route the alert, share the current status and hand over the evidence without rebuilding the story.
Alert routing
One incident. Four ways to reach the team.
Incident confirmedyoursite.com · 08:39
Email
Delivered
Slack
#website-alerts
Discord
Delivered
Webhook
200 OK
Client status page
A calm public answer.
yoursite.com
Live
All systems operational
30-day uptime
99.98%
Response
148ms
Change history
A clean record of what changed.
TLS renewedValid for 89 daysVerified
Consent changedEvidence attachedReview
Weekly briefTwo decisions surfacedSent
Clear limits
Useful coverage, without pretending to replace specialists.
Scavo joins routine website checks together. Deep engineering, security testing and formal audits still have their place.
Scavo is a good fit for
Website owners who need one dependable weekly view
Agencies looking after several client sites
Teams tired of separate uptime, audit and reporting routines
Keep specialist tools for
Application performance monitoring and server logs
Penetration testing and active security assessment
Formal accessibility or legal compliance sign-off
Your cookie choices
Essential cookies keep Scavo secure. Optional cookies remember your currency and show us which pages are useful.
Current choice: Decision needed
Essential
Needed for security, routing, and core platform behavior.
scavo_sessionScavo
Maintains secure authenticated session state and CSRF/session continuity.
Duration: Up to session timeout or browser close.
scavo_rememberScavo
Keeps you signed in on a trusted device when you explicitly choose remember me.
Duration: 7 days.
scavo_cookie_consentScavo
Stores your cookie preference (accept/reject) and consent version timestamp.
Duration: 180 days (configurable).
Preferences
Stores choices such as currency display for faster repeat visits.
scavo_currencyScavo
Remembers your preferred currency across pages and sessions.
Duration: 1 year.
Engagement
Helps us avoid repeating prompts and improve high-intent journeys.
scavo_exit_shownScavo
Prevents repeatedly showing the same exit-intent prompt.
Duration: 7 days.
Analytics
Measures useful interactions so we can improve product decisions.
scavo_analytics_idScavo
Anonymous visit/session identifier for pageview, funnel, and country/device analytics.
Duration: 30-minute rolling inactivity window.
Optional browser storage
These local-storage keys support optional features only after you allow them.
scavo_currencyScavo
Browser-side storage for optional preference memory or privacy-limited analytics state.
Duration: Until cleared, changed, or the feature no longer needs it.
scavo_analytics_sidScavo
Browser-side storage for optional preference memory or privacy-limited analytics state.
Duration: Until cleared, changed, or the feature no longer needs it.
This panel covers first-party cookies and optional browser storage used directly by Scavo. We do not load social-network widgets by default; if you open an external link, that service controls its own cookies and browser storage.
See Privacy Policy.