What an attacker finds on your site before you do?
Free website security, SEO, GDPR and accessibility audit — results in 30 seconds.
Over 150 automated checks across security, visibility, compliance and accessibility — built from real audit findings. Enter your address and in 30 seconds you know where the hole is.
- Free, no signup
- Results in under 30 seconds
- Checks from an ethical hacker's practice
Over 150 checks across 6 areas your AI skipped
One tool replaces hours of manual work and expensive agency audits. Every check is described in plain language — you know what's wrong, why it threatens you, and what to tell your AI to fix it.
Security
- API keys to paid services exposed in your site's code
- Security headers (CSP, HSTS, clickjacking protection)
- Publicly reachable backups, .git, .env and config files
- SSL certificate, its validity and TLS version
- Email security in DNS (SPF, DMARC, DNSSEC)
- Cookie safety (Secure, HttpOnly, SameSite)
- Form and login protection (CAPTCHA, honeypot, rate limit)
- Publicly reachable database panels (Adminer, phpMyAdmin)
Speed & performance
- Mobile load speed (Lighthouse)
- LCP, CLS and server response time
- Render-blocking scripts and styles
- Unused JavaScript and CSS, total page weight
- Compression and caching
- Image optimization and modern formats
Visibility (Google & AI)
- Structured data for Google (JSON-LD, Open Graph)
- Meta description, title, canonical and H1
- robots.txt and sitemap.xml
- Accessibility to AI search engines (ChatGPT, Claude, Perplexity, Gemini)
- An llms.txt file that helps AI understand you
- Crawlability and indexability
Source code & dependencies
- Outdated libraries with known vulnerabilities (jQuery, Bootstrap, Lodash…)
- A publicly reachable .git directory with your source
- Passwords and API keys hard-coded in the page
- Exposed config files and dependency manifests
- Leaked cloud access keys (AWS, S3)
Privacy, law & compliance
- Trackers (Google Analytics, Facebook Pixel) vs. consent
- GDPR cookie banner and the ability to manage it
- Business identification and registered address
- 14-day right of withdrawal (EU distance selling)
- Terms & conditions and contact details
- Out-of-court dispute resolution (ODR), EAA statement, US CCPA
Accessibility (EAA)
- Sufficient text contrast
- Alternative text for images
- Labels for links and buttons (screen readers)
- A set page language (lang)
- A viewport for mobile
- Correct heading order
And this is only a selection of the most important ones.
How much can it cost you not to check?
Tick what applies to you. A single overlooked mistake can swallow more than a whole year's web budget.
A rough estimate based on typical incident, fine or lost-profit costs. Real numbers tend to be higher.
Find out which of these threatens meBehind every check are real findings from practice
I break into websites legally — to help secure them before someone with bad intentions tries. Every check in this tool came from a real finding on a real website, not from generic theory. I know where sites built fast and with AI leak most often.
- Real findings from audits and testing, not preset theory
- Focused on sites built fast and with AI, where mistakes repeat
- In plain language: what's wrong, why it's a threat and exactly what to do
We take findings seriously — and your privacy just as much. We only inspect the site from the outside and store nothing beyond your report.
How it works
From address to report in three steps. No signup, no install.
Enter the address
Just your website's URL. No signup, no install.
We run the checks
Hundreds of tests across 6 areas run in parallel within seconds.
You get the report
A clear score, concrete issues by severity, and what to do about them.
What's in the report
No dry tables. A clear overview even a non-techie understands.
- Overall score and a score per area
- Concrete issues sorted by severity
- Measured values (LCP, page weight, TLS…)
- Plain-language explanation of why it matters
- A detailed report with fixes by email
overall website score
Frequently asked questions
Is the check really free?
Yes. The basic check is free, with no signup and no card — just your website address. You only enter an email if you want to unlock all findings and have the full report sent to you. A paid Pro tier with fix guides and site monitoring is still on the way.
Could it break my site or overload the server?
No. The check is lightweight — over a few seconds we send on the order of a few dozen requests, less than a single ordinary visitor. We don't change or delete anything on your site, and we don't try to bypass anything. Your traffic and speed stay unaffected.
Is it legal to have my site checked like this?
Yes. We only test what your site already serves to every visitor — the same headers, public files and server responses. We don't guess passwords, break past security, or overload the server. Just check sites you own or manage — that's fully your right; this tool isn't for snooping on others.
Do you store data from my site?
Nothing beyond your report. We inspect the site from the outside and store only the check results — the score and findings — so you can reopen the report via its link anytime. Even where we count, say, the number of publicly readable database records, we count only that number; we never read or store the data itself.
What do you do with my email? Will I get spam?
We use your email only to send your report and tips on fixing the findings. No spam, no selling to third parties, one-click unsubscribe. Giving your email is optional too — you'll see the basic findings without it.
Will anyone else see my results?
The report has a random unique link and we deliberately keep it out of search engines — only the people you send the link to can see it. Because it describes specific weaknesses of your site, we recommend not sharing it publicly.
How reliable are the findings? Could it be a false alarm?
Every check comes from a real audit finding, not generic theory. An automated test occasionally hits an edge case — say you protect a form in a way we can't see from the outside — so for each finding we explain how we reached it and how to verify it yourself. When in doubt, get in touch.
How are you different from Lighthouse and other free tools?
Lighthouse mainly measures the speed and SEO of a single page. Reconvio combines over 150 checks across 6 areas — server and code security, leaked keys and credentials, DNS and email, law and GDPR, accessibility and visibility — and explains it all in plain language. Instead of a table of numbers you get concrete issues ranked by how much they could cost you.
Does this replace a full security audit?
No, and it doesn't try to. Reconvio is a fast outside-in look that surfaces the most common and most expensive mistakes in half a minute. A deep audit with penetration testing and access to your code and infrastructure is a different league — when you need one, Reconvio is a good first step and we'll point you further.
Does it work on WordPress, Shopify or an e-shop?
Yes. We check the site the way a visitor and a search engine see it, so it doesn't matter what it runs on — WordPress, Shopify, Webflow, a custom build, or a site made with AI. Some checks — like GDPR, cookie consent and consumer-law duties — apply to any store selling to EU customers, wherever you're based.
You found a problem — what do I do next?
For each finding we explain what's wrong and why it puts you at risk. In the detailed report we add exactly what to do about it — often even what to paste into your own AI to fix it. For the harder ones we're preparing Pro with precise guides and site monitoring; if you need help right away, you can reach out directly.
Who's behind the tool and are the findings real?
Reconvio is built by ethical (white-hat) hacker Marek Křivan — he breaks into sites legally to help secure them before someone with bad intentions does. Every check comes from a real finding on a real site, not generic theory — mostly on sites built fast and with AI, where the same mistakes keep repeating.
Find out where your site has a hole
In seconds and for free. No signup, no strings attached.