Sitewarden

Technical audits · TLS · headers · DNS · SEO · accessibility

Know what is wrong with a site before your client does

Sitewarden runs 45 technical checks against any domain and turns the result into a scored, evidence-backed report. Run it once to win the engagement, then again to prove nothing regressed.

No account needed for the first three. Try , , .

individual checks
45individual checks
scored categories
6scored categories
per audit
~10sper audit
setup, agents or DNS changes
0setup, agents or DNS changes

How it works

  1. Enter a domain

    A bare hostname is enough. The audit follows redirects and reports the URL it settled on, so example.com works even when the site really lives at https://www.example.com.

  2. The engine runs

    It resolves DNS, completes a real TLS handshake, reads the response headers and parses the delivered markup. Three or four requests, identifying itself honestly, then it is gone.

  3. Hand over the report

    Every finding carries a severity, the evidence behind it and the change that resolves it. Print it and the interface furniture drops away, leaving something you can send to a client.

What a finding looks like

The report is built for the person who has to fix the problem, which means it shows the value it read rather than asking you to take its word for it.

Certificate is in date

high

The certificate expires in 9 days.

Fix: Renew now and set up automatic renewal so this cannot recur.

2026-09-03T11:41:08.000Z
Severity
Fixed per check, not guessed. It drives the score.
Observation
What we found, in plain language.
Fix
The specific change, not a link to a standards document.
Evidence
The raw value we read, so anyone can verify it.

What every audit covers

Each category is scored out of 100 and contributes to the overall grade by the weight shown.

Transport & TLS

30%

Certificate validity and expiry, the trust chain, negotiated protocol version and cipher, HSTS strength, and whether plain HTTP is actually redirected.

Security headers

25%

Content-Security-Policy including unsafe directives, clickjacking protection, MIME sniffing, Referrer-Policy, Permissions-Policy, COOP, version disclosure and cookie flags.

DNS & email authentication

15%

Nameserver redundancy, SPF syntax and its all mechanism, DMARC presence and policy strength, CAA restrictions, and the MX records behind the domain.

Content & SEO

15%

Title and meta description length, canonical URL, heading structure, Open Graph tags, robots.txt and sitemap reachability, charset and accidental noindex.

Accessibility spot checks

10%

Document language, image alt text, labelled form fields, a zoomable viewport, icon-only links, skip links and positive tabindex values.

Delivery & performance

5%

Time to first byte, compression, document weight, caching policy, redirect chain length, render-blocking scripts and lazy-loading opportunities.

The complete catalogue, check by check, is on the features page.

Three moments it earns its keep

Winning the engagement

Run the audit before the first call. Arriving with a scored report and four specific problems is a different conversation from arriving with a rate card.

The pre-launch gate

One pass before a site goes live catches the expired staging certificate, the accidental noindex and the missing security headers — the three that get noticed by everyone except you.

Proving nothing regressed

A redeploy that quietly drops a header is invisible until it is not. Stored history means you can show a client the before and the after, with dates.

You could do all of this by hand

And for one domain, you probably should — every check here is a command you already know. The argument for paying is the tenth domain, the report the client actually reads, and remembering to look again in March.

The same checks performed manually and by Sitewarden
CheckBy handSitewarden
Certificate expiry and chainopenssl s_client -connect …Checked, with days remaining
Security headerscurl -I, then read carefullyParsed, including inside the CSP
SPF, DMARC, CAAdig TXT, three timesChecked, with policy strength
Markup and accessibilityView source and squint45 checks, scored
Doing it again next monthRemember toStored history, dated
Giving it to a clientPaste terminal outputA report they can read

Pricing

Monthly, in euros, cancel any time. Taxes are calculated at checkout.

Trial

Kick the tyres on a couple of domains before paying for anything.

Free

  • 5 audits in total
  • All check categories
  • Shareable result page
Start free

Starter

For the freelancer who looks after a handful of client sites.

€19 / month

  • 150 audits / month
  • 5 monitored domains
  • Full TLS, header, DNS, SEO and accessibility checks
  • Email support
Choose Starter

Pro

For consultants who report to clients on a schedule.

€49 / month

  • 1 000 audits / month
  • 25 monitored domains
  • Client-ready printable reports
  • Priority email support
  • Scheduled re-audits and regression history in development
Choose Pro

Agency

For teams running audits across a whole portfolio.

€149 / month

  • 10 000 audits / month
  • 250 monitored domains
  • Everything in Pro
  • Onboarding call
  • White-label reports in development
Choose Agency

Full details, including what happens when you hit a quota, are on the pricing page.

Frequently asked questions

What exactly do I get when I subscribe?
Immediate access to the web application at the plan's quota. You enter a domain, the audit runs in about ten seconds, and you get a scored report with every finding, the evidence behind it and the change that fixes it. Reports are stored in your account so you can show a client the before and after.
Is this a scanner or a consulting service?
It is software. Nobody reviews your site by hand — the checks are automated and run against the live domain each time you ask for them. Support is limited to helping you use the product.
How is this different from running the checks myself?
Every check here is something you could do with openssl, dig and curl. The product is that it does all of them at once, keeps the history, and produces something you can put in front of a non-technical client. If you enjoy the terminal, keep using it — this is for the reporting, not the discovery.
Will it slow down or damage the site being audited?
No. An audit is three or four ordinary GET requests, one DNS resolution and one TLS handshake, sent once when you press the button. It never authenticates, never submits a form, and never probes for vulnerabilities.
Do you audit sites I do not own?
You confirm at sign-up that you audit only domains you own or have permission to audit. The crawler identifies itself as SitewardenBot and is documented publicly so any site owner can identify and block it.
Can I cancel whenever I want?
Yes. Subscriptions are month to month and cancel from the billing portal in one click. You keep access until the end of the period you have already paid for, and the first 14 days are covered by a money-back guarantee.

Still unsure? Ask us before you buy — we answer within one business day.

Audit a domain you are responsible for

Five audits on the free trial, no card, no sales call. If the first report tells you nothing you did not already know, you have lost ten seconds.