These rows come from the live scan catalogue. If a check changes in Scavo, it changes here too.
Included in monitoring
Security · 8 checks
Active library
Protect visitor trust. Every request to your site should be encrypted, hardened, and free of mixed content.
SSL certificateValidates your certificate chain, expiry window, and protocol strength.Included
HTTPS redirectConfirms all HTTP traffic redirects to HTTPS with no mixed chains.Included
Security headersTests for X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.Watch
Cookie security flagsChecks whether session and auth cookies use Secure, HttpOnly, and SameSite protections.Watch
Mixed contentDetects insecure resources loaded over HTTP on an HTTPS page.Included
Content Security PolicyChecks for a CSP header or meta tag that limits script injection vectors.Priority
HSTSVerifies Strict-Transport-Security is present with a sensible max-age and includeSubDomains.Included
Security.txtChecks for a current RFC 9116 vulnerability-reporting route at the standard well-known URL.Consider
Meta descriptionLength, uniqueness, and keyword relevance of your meta description tag.Included
Title tagValidates presence, length, and distinctiveness of your page title.Included
H1 tagChecks you have exactly one H1 and it aligns with the page topic.Included
Canonical tagConfirms a self-referencing canonical exists to prevent duplicate-content issues.Included
Structured dataValidates JSON-LD schema markup for rich snippets in search results.Watch
SitemapVerifies your XML sitemap exists, parses correctly, and is referenced in robots.txt.Included
Twitter cardsChecks for twitter:card, twitter:title, and twitter:image meta tags.Priority
HreflangValidates international targeting tags for multi-language sites.Included
Meta robotsEnsures no accidental noindex or nofollow directives are blocking crawlers.Included
Heading structureChecks heading hierarchy (H1 to H6) for logical order and SEO best practice.Watch
Internal linksScans for broken internal links, orphan pages, and redirect chains.Included
Content policy riskFlags thin, overly templated, or link-heavy pages that look risky under modern search spam policies.Watch
Indexability conflictsDetects contradictions between canonical, robots meta, and sitemap signals.Included
Page load timeMeasures time-to-interactive from a real browser rendering pass.Included
Full page load estimateEstimates total resource weight and load waterfall for the complete page.Watch
CompressionChecks modern text compression is enabled for HTML, CSS, JS, JSON, and similar responses.Included
Image optimisationValidates format (WebP/AVIF), sizing, lazy-loading, and responsive srcset usage.Priority
Image payload budgetFlags pages where total image weight exceeds performance budgets.Watch
CachingValidates Cache-Control headers and asset fingerprinting for repeat visits.Included
MinificationDetects unminified CSS and JavaScript that inflates page weight.Included
Server response timeMeasures TTFB and flags slow server responses before they cascade.Included
Core Web VitalsReal CrUX data for LCP, INP, and CLS - the metrics Google uses for ranking.Watch
Render-blocking budgetIdentifies scripts and stylesheets that block first paint.Included
Image alt textEnsures every meaningful image has descriptive alternative text.Priority
Colour contrastValidates foreground/background contrast ratios meet WCAG AA thresholds.Watch
ARIA labelsChecks interactive elements have proper ARIA attributes for screen readers.Included
Form labelsEnsures every input, select, and textarea has an associated label.Included
Landmark rolesVerifies semantic landmarks (nav, main, footer) for assistive navigation.Included
Skip linksChecks for a skip-to-content link so keyboard users can bypass navigation.Included
Mobile text readabilityValidates font sizes and line heights are legible on small screens.Included
Mobile tap targetsEnsures buttons and links are large enough and spaced for touch input.Watch
AI Visibility SignalsCross-checks page-level AI opt-outs, llms.txt, and robots rules so your signals do not contradict each other.Included
Content SignalsReads Content-Signal directives in robots.txt for AI training, search, and AI input preferences.Watch
Markdown NegotiationTests whether pages can return a markdown or plain-text variant when agents explicitly request one.Watch
Agent Link HeadersChecks Link headers for agent-relevant discovery targets such as API catalogs or service descriptions.Included
Web Bot AuthVerifies the well-known signed key directory used by friendly bots and agents to authenticate their requests.Included
Agent Protocol DiscoveryLooks for public MCP, Agent Skills, A2A, and API Catalog discovery documents.Watch
OAuth Resource DiscoveryChecks for OAuth and OpenID metadata so agents can discover protected-resource auth flows cleanly.Watch
AI Bot Access ParityCompares bot responses so AI crawlers receive the same indexable page signals as standard search bots.Included
LLMs.txt QualityChecks whether your llms.txt exists, is parseable, and includes useful machine-readable guidance.Watch
AI Crawler PolicyValidates explicit robots directives for common AI crawlers to avoid accidental allow/deny ambiguity.Watch
AI Snippet Control SafetyFlags conflicting snippet directives that reduce reliable AI and search snippets.Included
AI Citation ReadinessAssesses canonical and structured-data citation signals so answers can attribute your domain correctly.Included
AI JS Dependency RatioEstimates how JS-heavy your page is versus extractable HTML to highlight crawler-readability risk.Watch
AI Token BudgetMeasures whether pages have enough structured text for reliable retrieval and summarization.Included
AI ChunkabilityChecks heading and section structure so long pages split into clean retrieval chunks.Included
Domain expiryAlerts weeks before your domain registration lapses.Included
Nameserver changesDetects unexpected nameserver switches that could signal hijacking.Included
DNS A record driftMonitors your A/AAAA records for silent IP changes.Included
Email trust (SPF/DKIM/DMARC)Validates email authentication records to prevent spoofing.Watch
CMS fingerprintIdentifies your CMS and flags known security patterns for that platform.Included
Robots.txtValidates syntax, crawl directives, and sitemap references.Included
Redirect chain hygieneChecks that canonical redirects resolve quickly without multi-hop chains or loops.Watch
404 response handlingTests missing URLs so broken paths return a real 404 instead of a soft success page.Included
Analytics instrumentationConfirms analytics is present in a controlled, recognizable way so visits and conversions are measurable.Watch
Viewport metaConfirms a mobile viewport meta tag exists with correct settings.Included
FaviconChecks for a valid favicon in multiple formats for browser tabs and bookmarks.Included
DoctypeEnsures a valid HTML5 doctype for standards-mode rendering.Included
CharsetValidates UTF-8 character encoding is properly declared.Included
Language attributeChecks the HTML lang attribute for assistive technology and search engines.Included
Browser runtime healthCatches uncaught JavaScript errors and failed first-party assets during a real rendered load.Watch
Mobile viewport widthVerifies content fits within the viewport without horizontal scrolling.Included
Open GraphValidates og:title, og:description, og:image, and og:url for rich social previews on Facebook, LinkedIn, and others.Included
Social linksDetects social profile links and validates they're accessible and properly structured.Watch
Cookie consent bannerDetects a consent interface and validates it meets GDPR, PECR, and CCPA requirements.Watch
Pre-consent trackingChecks whether trackers fire before the visitor grants consent - a common GDPR violation.Priority
Post-reject trackingVerifies that trackers stop after consent is declined or withdrawn.Included
Privacy policy disclosureConfirms a privacy policy is linked, accessible, and mentions key regulation frameworks.Included
Disclosure reconciliationCross-checks disclosed data practices against actual trackers found on the page.Watch
California opt-outValidates CCPA “Do Not Sell” link presence and Global Privacy Control signal handling.Included
Sensitive tracker riskFlags high-risk trackers that may process sensitive data categories without explicit consent.Included
Compliance guidance only - not a substitute for professional legal advice.
Uptime and incidents
See the outage. See the recovery.
Failed probes are confirmed before Scavo alerts the team. Recovery is checked before the incident closes.
Hourly on SoloFor sites where a slower cadence is enough.
Flexible (1 min to 1 hr) on TeamFor important sites and faster detection.
Recovery verificationScavo checks the site is genuinely back before closing an incident.
yoursite.com
Last checked 24s ago
30-day uptime99.98%
Response time148ms
Open incidents0
Recovery confirmed08:42 · 2 successful checks after a 3m 14s incident
Closed
scavo
Weekly website brief
yoursite.com · Monday 09:12
Two things changed. One can wait.
Your site stayed online. This week's report found one consent change worth reviewing and one lower-priority crawler signal.
1
Review consent behaviourMedium effort · visitor analytics may be affected
78 checks passed Domain renewal confirmed
Open the evidence
Reporting without dashboard duty
The brief reads like a decision, not an audit.
Related evidence stays together. Changes rise above repeated healthy results. Lower-priority work stays lower.
Weekly or monthly delivery
Combined agency digest or one email per site
Fix guidance, likely impact and effort
Historical reports for before-and-after checks
After Scavo finds something
The result goes somewhere useful.
Send the incident, share the current status and keep the evidence trail. No copy-and-paste handover required.
Alert routing
One incident. Four ways to reach the team.
Incident confirmedyoursite.com · 08:39
Email
Delivered
Slack
#website-alerts
Discord
Delivered
Webhook
200 OK
Client status page
A calm public answer.
yoursite.com
Live
All systems operational
30-day uptime
99.98%
Response
148ms
Change history
A clean record of what changed.
TLS renewedValid for 89 daysVerified
Consent changedEvidence attachedReview
Weekly briefTwo decisions surfacedSent
Honest scope
Broad watch. Honest boundaries.
Scavo joins routine website monitoring together. It does not pretend to replace deep engineering or professional sign-off.
Scavo is a good fit for
Website owners who need one dependable weekly view
Agencies looking after several client sites
Teams tired of separate uptime, audit and reporting routines
Keep specialist tools for
Application performance monitoring and server logs
Penetration testing and active security assessment
Formal accessibility or legal compliance sign-off
Your cookie choices
Essential cookies keep Scavo secure. Optional cookies remember your currency and show us which pages are useful.
Current choice: Decision needed
Essential
Needed for security, routing, and core platform behavior.
scavo_sessionScavo
Maintains secure authenticated session state and CSRF/session continuity.
Duration: Up to session timeout or browser close.
scavo_rememberScavo
Keeps you signed in on a trusted device when you explicitly choose remember me.
Duration: 7 days.
scavo_cookie_consentScavo
Stores your cookie preference (accept/reject) and consent version timestamp.
Duration: 180 days (configurable).
Preferences
Stores choices such as currency display for faster repeat visits.
scavo_currencyScavo
Remembers your preferred currency across pages and sessions.
Duration: 1 year.
Engagement
Helps us avoid repeating prompts and improve high-intent journeys.
scavo_exit_shownScavo
Prevents repeatedly showing the same exit-intent prompt.
Duration: 7 days.
Analytics
Measures useful interactions so we can improve product decisions.
scavo_analytics_idScavo
Anonymous visit/session identifier for pageview, funnel, and country/device analytics.
Duration: 30-minute rolling inactivity window.
Optional browser storage
These local-storage keys support optional features only after you allow them.
scavo_currencyScavo
Browser-side storage for optional preference memory or privacy-limited analytics state.
Duration: Until cleared, changed, or the feature no longer needs it.
scavo_analytics_sidScavo
Browser-side storage for optional preference memory or privacy-limited analytics state.
Duration: Until cleared, changed, or the feature no longer needs it.
This panel covers first-party cookies and optional browser storage used directly by Scavo. We do not load social-network widgets by default; if you open an external link, that service controls its own cookies and browser storage.
See Privacy Policy.