WEBSCOPEPILOT
Understanding your website check
What we actually check
A quick check makes a GET request to one public page, follows at most five redirects, and downloads at most 512 KiB. We inspect HTTP status, TLS verification, security-header presence and HTML metadata. We do not execute JavaScript, scan for exploits or test private pages.
Read findings in context
High findings indicate an observed HTTP error or unencrypted final page. Medium findings include a missing title or a certificate near expiry. Information findings suggest a configuration review. We do not combine them into an arbitrary security score. A clean report is not a security guarantee.
Security headers
Content Security Policy controls where browsers can load resources. Its absence alone does not prove a vulnerability. Begin with a policy tailored to your site and test using report-only mode. X-Content-Type-Options: nosniff tells a browser to respect content types. HSTS tells returning browsers to require HTTPS; enable it only after validating HTTPS and considering subdomains.
Metadata and accessibility indicators
A useful title describes a page to visitors, browser tabs and search engines. Descriptions may appear in search results, but search engines choose their own snippets. A missing canonical is not automatically a fault. Missing image alt attributes and page language deserve a manual accessibility review; this is not a full accessibility audit.
Understand timing
Response time includes DNS lookup, TLS and downloading the response from this server. It varies with location, page size and network conditions. It is not Core Web Vitals, a browser rendering measurement or proof that all users experience the same speed.
Monitoring and incidents
Free accounts monitor one website approximately hourly. A failed check is retried after about two minutes before an incident is opened. A later successful check closes it. These observations come from one location; firewall blocks and DNS failures can resemble downtime. Alerts appear in your dashboard. We do not currently send email or browser push notifications.
Recovery and privacy
Save the recovery code shown once at registration. A recovery consumes and replaces that code and resets the password. Reports are private to the creating browser session or account. Enable a public status page only if you want its website address and incident times to be public.