SiteScan.top

How can we help?

Find answers to common questions about SiteScan.top.

How SiteScan.top works

A scan starts with nothing but an address. SiteScan.top requests the page, reads the HTML the server returns, follows the internal links it finds and repeats that until the page budget is used up. There is nothing to install, no tag to add to your site and no account to create — a surface scan is free and anonymous.

Every page that comes back goes through the same set of analysers: response status and timing, title and description, canonical and hreflang, heading structure, images and their alt text, forms and their fields, internal and external links, security headers, structured data, and the validity of the markup itself.

What comes back is one report: an overall score, a score per category, every issue with the pages it was found on, the quick wins ordered by how much they pay back per minute of work, and the tests worth running next. The report keeps a stable address, so you can send it to a colleague or open it again after a fix and compare.

A scan, step by step

1. You paste an address

Type a domain, with or without https://, and start the scan. The address has to be publicly reachable: a site behind a login, a VPN or a private IP range cannot be crawled from the outside.

2. The crawler walks the site

The entry page is fetched first, then the internal links found on it — five pages by default and ten at most. Pages are read one after another with the SiteScanBot user agent, so a scan behaves like one careful visitor rather than a load test.

3. Every page is analysed

Each page is scored on accessibility, performance, SEO, security, forms, links, infrastructure and HTML validity. A category with nothing measurable on it is reported as not measured rather than filled in with a guess.

4. The report is written and stored

Findings are grouped by issue rather than by page, so a missing alt attribute on nine images is one item with nine locations. The finished report is stored and shows up in the public list of recent scans.

How to read the scores

Scores are diagnostics, not grades. They exist to tell you where to look first, and they compare a site with what the checks expect — never with another site.

The overall score
Each measured category starts at 100 and loses points for every issue found, weighted by severity and spread over the pages crawled. The overall score is the average of the measured categories, so one badly broken area cannot hide behind eight healthy ones. 90 and above is excellent, 70 to 89 is good, below 70 needs work.
Category scores
Nine categories are reported: accessibility, performance, SEO, security, forms, links, console, infrastructure and HTML. Open any of them to see the issues behind the number and the exact pages they were measured on.
Severity
Issues are critical, high, medium or low. Critical and high mean something is already broken for visitors: a dead link, a form with no action, a page answering with an error. Medium and low are usually missing metadata or markup that will cost you later rather than today.
Quick wins
Quick wins rank the findings by payoff per minute of work, so the top of that list is where an hour of your time buys the largest change in the score. Each one names the pages to change and what improves once you have.

Frequently asked questions

What does SiteScan.top scan for?
SiteScan.top performs comprehensive testing including broken link detection, JavaScript console error analysis, form testing, accessibility audits (WCAG), performance metrics (Core Web Vitals), SEO analysis, and security header checks.
How many pages does one scan cover?
A free scan reads five pages by default and ten at most: the address you entered plus the internal links found on it. The budget is per scan rather than per day, and larger crawls belong to the paid audits.
How long does an audit take?
Surface audits typically complete in 1-3 minutes. Deep audits with full form testing and comprehensive analysis may take 5-10 minutes depending on site size.
Why does my scan say it is waiting?
Five sites are crawled at the same time; when every slot is busy, new scans queue instead of being refused. The page shows your position and starts on its own as soon as a slot frees up — there is nothing to click.
Why did I get a report I did not just run?
A report is reused for fifteen minutes, so a shared link, a reload and a second visitor do not crawl the same site three times over. Use the rescan button to force a fresh crawl once you have changed something.
What is the difference between Surface and Deep audits?
Surface audits scan all pages for broken links and console errors. Deep audits add AI-powered form testing, full accessibility scans, SEO analysis, and detailed reproduction steps for each issue.
How exactly is the score calculated?
Every measured category starts at 100 and loses points per issue, weighted by severity and averaged over the pages crawled. The overall figure is the mean of the measured categories, so it moves when a whole area improves rather than when one page does.
Why is the console score empty?
Console errors only surface when a browser engine executes the page's JavaScript. A run that could not do that reports the category as not measured instead of filling the gap with a guess.
Is my website data secure?
Yes. We only access publicly available pages on your site. We do not store credentials, and audit data is encrypted at rest. You can delete your audit history at any time.
What do you store about a site I scanned?
The report itself: the pages crawled, the values measured on them and the issues raised. Reports appear in the public list of recent scans, so do not scan an address you would rather not see listed — and write to support if one needs removing.
Can I audit password-protected pages?
Currently, SiteScan.top only audits publicly accessible pages. Support for authenticated page testing is on our roadmap for enterprise plans.
Can I scan a staging site or localhost?
Only addresses that resolve publicly can be scanned: localhost, private ranges and anything behind a VPN are refused. A staging site on a public domain works fine, and pages behind basic auth are reported as unauthorised rather than crawled.
How do credits work?
A free account includes one surface audit a month. Beyond that an audit costs credits — 1 for a surface audit, 5 for a deep one — and credits come in packs: 10 for $25, 30 for $60, 100 for $150. They do not expire.
What browsers does SiteScan.top test with?
SiteScan.top uses headless Chromium for testing, which represents the majority of modern browser usage. Results are applicable to Chrome, Edge, and most Chromium-based browsers.
In which languages is a report available?
The interface and every report are available in English, Russian, Polish and German. A site is crawled once and the findings are written out in the language you are reading, so one report can be shared across a team that does not share a language.
Can I export my audit results?
Yes. Deep audit reports can be exported as PDF documents. The report includes all issues, severity ratings, and reproduction steps.
Is there an API?
The report page is served by a JSON endpoint, and a documented, versioned public API is on the roadmap. Until it ships, write to support if you need programmatic access and we will tell you what is stable enough to build on.
A finding does not look right. What now?
Every issue carries the measured values it was raised from, so you can check it against the page yourself. If the numbers are right but the conclusion is wrong for your case, send us the report link and we will look at the rule behind it.
How often should I scan?
Before a release and right after it is the pair that catches the most: the first shows what you are shipping on top of, the second whether the deploy broke something. Beyond that, once a month is enough for a site that changes slowly.

What a scan does not do

Automated testing finds what can be measured from the outside. It will not tell you whether your copy makes sense, whether a checkout charges the right amount, or whether someone using a screen reader can finish a task — a large share of accessibility barriers still needs a person to confirm.

The crawl also sees only what a visitor sees: pages behind a login, addresses that nothing links to, and content injected long after load can be missing from the report. Read a clean report as “nothing measurable is broken”, not as a certificate.

Still have questions?

Send us a message and we'll respond within 24 hours.