Free website auditFind every bug.Ship every fix.

25 engines audit SEO, AI search readiness, performance, security and accessibility across your whole site in a real browser — then AI writes the code fixes, SEO rewrites and GEO fixes for your exact site — ranked by impact, in a branded PDF.

  • 1 free full report · then $1.49
  • No signup for the preview
  • Results in ~5 minutes
  • AI code, SEO & GEO fixes
BugViso

bugviso.com

42 pages scanned · 1m 48s

14 issues · 14 AI fixes readyAffected
  • CriticalButtons without an accessible nameAccessibility7 pages
  • HighGPTBot blocked by edge firewall (403)AI searchSite-wide
  • HighBroken internal linksLinks3 links
  • MediumRender-blocking third-party scriptPerformance12 pages
  • LowOrphan page with no inbound linksSEO1 page
82Grade B
  • SEO91
  • Performance78
  • Accessibility64
  • Security95
  • AI search58
audit engines
25
checks on every page
74
disciplines in one report
7
from URL to results
~5 min
  • AI crawler access
  • Content AI bots can see
  • llms.txt file
  • Brand identity & citations
  • Technical SEO
  • Keyword focus
  • Duplicate content
  • Internal links
  • Backlinks
  • Titles & meta tags
  • Core Web Vitals
  • Slow-network testing
  • HTTPS & security headers
  • Cookie consent (GDPR / CCPA)
  • Accessibility (WCAG 2.1 AA)
  • Mobile experience
  • Visual layout
  • React / Next.js mismatches
  • JavaScript errors
  • Failed requests
  • Broken links & images
  • Whole-site crawl
  • Prioritised fix list
  • PDF report
  • Email delivery

How a scan runs

One URL in. A prioritised fix list out.

  1. 01

    Crawl

    Reads sitemap.xml and robots.txt, then walks same-host links breadth-first to map the whole site — not just the homepage.

    sitemap · bfs · depth-limited

  2. 02

    Render

    Each page loads in real headless Chromium on desktop and mobile, throttled like a mid-range phone on a slow network.

    chromium · 4× cpu · 3g

  3. 03

    Audit

    25 engines inspect every page: axe-core accessibility, Web Vitals, TLS, SimHash duplicates, SSIM visual diffs and AI-bot probes.

    74 checks per page

  4. 04

    FixAI-written

    Findings are scored, ranked by impact and turned into copy-paste fixes — then packaged into a branded PDF you can hand to anyone.

    playbook · ai fixes · pdf

The engine room

25 engines. 7 disciplines. One scan.

Every engine runs on every scan — no add-ons, no five tools to stitch together. Findings from all of them land in one scored, prioritised report.

Every check, in detail
  1. Discipline 01 / 07

    AI search readiness

    12

    checks · 4 engines

    • AI crawler accessflagship

      Makes sure AI bots aren’t blocked by robots.txt or your firewall.

    • Content AI bots can seenew

      Compares what bots receive before JavaScript runs with what visitors see.

    • llms.txt fileAInew

      Checks your guide file for AI tools — and AI drafts one if it’s missing.

    • Brand identity & citationsnew

      Checks the signals that help AI recognise your brand and quote you.

    Explore all 12 checks
  2. Discipline 02 / 07

    SEO & content

    18

    checks · 6 engines

    • Technical SEO

      Structured data, canonical and language tags, headings and image alt text.

    • Keyword focusnew

      Finds each page’s main keyword and checks it’s used in the right places.

    • Duplicate contentnew

      Finds pages that are copies or near-copies of each other.

    • Internal linksnew

      Maps how your pages link together and finds pages nothing links to.

    • Backlinksnew

      Reviews the sites that link to you and flags spammy links.

    • Titles & meta tags

      Page titles, descriptions, social previews and heading order.

    Explore all 18 checks
  3. Discipline 03 / 07

    Speed & Core Web Vitals

    6

    checks · 2 engines

    • Core Web Vitals

      Google’s loading, responsiveness and layout-stability scores, measured live.

    • Slow-network testing

      Reloads pages on slow mobile connections and finds unused code.

    Explore all 6 checks
  4. Discipline 04 / 07

    Security & privacy

    6

    checks · 2 engines

    • HTTPS & security headers

      Your certificate, HTTPS setup and the headers that protect visitors.

    • Cookie consent (GDPR / CCPA)

      Flags tracking cookies and pixels that load before visitors agree.

    Explore all 6 checks
  5. Discipline 05 / 07

    Accessibility & mobile

    6

    checks · 2 engines

    • Accessibility (WCAG 2.1 AA)

      Barriers for keyboard and screen-reader users, ranked by impact.

    • Mobile experience

      Loads each page as a phone would and checks it’s easy to read and tap.

    Explore all 6 checks
  6. Discipline 06 / 07

    Visual & code quality

    15

    checks · 5 engines

    • Visual layout

      Screenshots your pages and spots broken or shifted layouts.

    • React / Next.js mismatches

      Catches pages where the server and browser render different content.

    • JavaScript errors

      Every script error, with the file and line it came from.

    • Failed requests

      Files that fail to load, or load over an insecure connection.

    • Broken links & images

      Tests every internal and external link and image.

    Explore all 15 checks
  7. Discipline 07 / 07

    Crawl & reporting

    11

    checks · 4 engines

    • Whole-site crawl

      Finds your pages through the sitemap and links, then checks each one.

    • Prioritised fix listAI

      Turns every finding into a do-this-next list with AI-written, copy-paste fixes.

    • PDF report

      A branded report with your score, grade and every fix, ready to share.

    • Email deliverynew

      Sends the report to your inbox as soon as the scan finishes.

    Explore all 11 checks

Findings are cheap. Fixes ship.

Every issue arrives with the code that fixes it.

The remediation engine pairs each problem with copy-paste markup, headers, config or commands. Then AI rewrites every fix with your site’s real code and content — ready to paste, not a generic tip.

What AI writes for every scan

Three sets of fixes, written from your pages’ real code and copy — ready to paste.

Written for your site — not generic advice
  • AI code fixes

    For developers

    • Copy-paste code in your real markup
    • Step-by-step instructions for each fix
    • Speed, accessibility, security & hydration
  • AI SEO

    For search engines

    • Rewritten titles and meta descriptions
    • Stronger H1s and keyword clusters
    • JSON-LD validated before it ships
  • AI GEO

    For AI answers

    • Why AI engines can or can’t cite you
    • A tailored llms.txt for your site
    • Tips to write answer-ready content

Plus a plain-English summary that tells you what to fix first and which wins are quick.

All in your PDF report

Real fixes from the remediation library

06 categories

  1. AI Search Readiness

    01 / 06
    Detected

    GEO 2.0: Cloudflare AI Bot Allow Rule & Standard /llms.txt Manifest

    Over 70% of modern sites unintentionally block AI crawlers via Cloudflare Managed Rules (WAF 403) or render empty SPA shells without an llms.txt knowledge manifest.

    Fix ships as
    YAML
    Impact
    Eliminates edge 403 WAF blocks and maximizes citation coverage in ChatGPT, Claude & Perplexity
    before
    # robots.txt looks fine, BUT Cloudflare WAF silently blocks AI bots with 403:
    # CF-WAF Rule: Block Automated Traffic (Managed Challenge) -> GPTBot 403 Forbidden!
    # Result: 0 citations in ChatGPT Search & Perplexity
    after · yaml
    # 1. /llms.txt - Standard Generative Engine Manifest
    # https://yourdomain.com/llms.txt
    # Core Technical Architecture
    > Modern high-performance web platform audited by BugViso.
    
    ## Primary Documentation Clusters
    - [API Reference](/docs/api): REST endpoints & webhooks
    - [System Architecture](/docs/architecture): Component pipelines
    
    # 2. Cloudflare WAF Custom Rule (Expression):
    # (cf.client.bot and http.user_agent contains "GPTBot") or 
    # (http.user_agent contains "ClaudeBot") -> Action: Skip (Bypass WAF)
  2. SEO & Content Intelligence

    02 / 06
    Detected

    Structured JSON-LD Schema & Semantic Graph

    Search engines and AI models rely on Schema.org structured data to verify company identities, products, and author authority. Missing schema reduces rich snippet CTR.

    Fix ships as
    HTML
    Impact
    Enables Google Rich Results & instant machine-readable knowledge graph
    before
    <!-- Missing structured data -->
    <h1>Core Web Vitals Guide</h1>
    after · html
    <script type="application/ld+json">
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "headline": "Core Web Vitals Guide",
      "author": { "@type": "Person", "name": "Technical Lead" },
      "datePublished": "2026-09-01",
      "publisher": { "@type": "Organization", "name": "BugViso" }
    }
    </script>
  3. Performance & Core Web Vitals

    03 / 06
    Detected

    Sub-Millisecond LCP & Non-Blocking INP Scheduling

    Heavy render-blocking hero images delay LCP (>2.5s), while long JavaScript tasks freeze the main thread, causing severe INP (Interaction to Next Paint) latency.

    Fix ships as
    TypeScript
    Impact
    Stabilizes LCP < 1.2s and keeps INP < 100ms for green PageSpeed vitals
    before
    // Unoptimized image loading
    <img src="/hero.png" />
    after · typescript
    // 1. High-priority LCP hero image with eager decoding
    <img 
      src="/hero.webp" 
      fetchpriority="high" 
      loading="eager" 
      decoding="async" 
    />
    
    // 2. Yield to browser main thread during heavy calculations
    await (window.scheduler?.yield?.() || new Promise(r => setTimeout(r, 0)));
  4. Security & Privacy

    04 / 06
    Detected

    Enterprise HTTP Security & Transport Headers

    Missing HSTS, Content Security Policy (CSP), or X-Frame-Options leaves web applications vulnerable to clickjacking, MIME sniffing, and mixed-content blocking.

    Fix ships as
    TypeScript
    Impact
    Eliminates clickjacking, script injection, and transport vulnerabilities
    before
    // Server responses without defensive security headers
    app.get('/', (req, res) => res.send('OK'));
    after · typescript
    // Defensive security headers middleware
    const securityHeaders = {
      "Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
      "X-Content-Type-Options": "nosniff",
      "X-Frame-Options": "SAMEORIGIN",
      "Referrer-Policy": "strict-origin-when-cross-origin",
      "Content-Security-Policy": "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"
    };
  5. Accessibility & Mobile

    05 / 06
    Detected

    WCAG 2.1 AA Accessible Action Markup

    Icon-only action buttons without accessible names cause automatic screen-reader failure and WCAG 2.1 AA violations.

    Fix ships as
    TypeScript
    Impact
    100% Lighthouse Accessibility score & ADA/WCAG legal compliance
    before
    // Inaccessible icon button
    <button onClick={handleDelete}>
      <TrashIcon />
    </button>
    after · typescript
    // WCAG 2.1 AA Compliant with keyboard focus ring & sr-only label
    <button 
      onClick={handleDelete}
      aria-label="Delete audit report"
      className="focus-visible:ring-2 focus-visible:ring-violet-500 outline-none"
    >
      <TrashIcon aria-hidden="true" />
      <span className="sr-only">Delete audit report</span>
    </button>
  6. Visual & Code QA

    06 / 06
    Detected

    React & Next.js SSR Hydration Mismatch Hunter

    Minified React errors (#418 / #423 / #425) occur when server-rendered HTML differs from client-rendered state (e.g. timestamps, localStorage, window dimensions).

    Fix ships as
    TypeScript
    Impact
    Eliminates white-screen layout shifts and hydration bailouts
    before
    // Causes server/client mismatch crash
    function Timestamp() {
      return <div>Rendered at: {new Date().toLocaleTimeString()}</div>;
    }
    after · typescript
    // Solution A: suppressHydrationWarning for dynamic text
    <time suppressHydrationWarning>{timeString}</time>
    
    // Solution B: Client-only mounting guard
    const [mounted, setMounted] = useState(false);
    useEffect(() => setMounted(true), []);
    if (!mounted) return <SkeletonLoader />;

From finding to fixed

  1. 01

    Ranked by impact

    Critical, high and quick-win tiers with effort estimates, so the first fix is always the one that matters most.

  2. 02

    Fixes travel with the report

    AI fixes, code snippets, llms.txt and JSON-LD all land in the PDF, so whoever implements them has everything in one file.

  3. 03

    Re-audit in one click

    Every scan is kept in your audit records. Re-run a domain after shipping to confirm the fixes landed and the score moved.

AI search readiness · GEO

Can ChatGPT, Claude and Perplexity actually read your site?

robots.txt can say yes while your CDN says no. BugViso probes with real AI-crawler user agents, compares server HTML against the hydrated DOM, validates llms.txt and scores how citable your content is. Then AI drafts the llms.txt and structured data to fix it.

How the GEO engines work

AI crawler probe

bugviso.com

User agentrobots.txtLive edge
GPTBotallowed403 · WAF
ClaudeBotallowed200 OK
PerplexityBotallowed200 OK
Google-Extendeddisallowedopted out

SSR parity

4%

empty SPA shell

llms.txt

404

not published

Citability

58

of 100

AI fix → add a WAF skip rule for verified AI bots, prerender the SPA and publish /llms.txt

Under the hood

Built like infrastructure, not a browser plug-in.

The same pipeline powers the free scan, scheduled re-scans and every report — engineered for accuracy first, then speed.

Slow 3G · 500 kbps · 400 msFast 3G · 1.6 Mbps · 150 ms4× CPU slowdown

Real browser, real metrics

Every page renders in headless Chromium on desktop and mobile, with CPU and network throttling over CDP — not a static HTML fetch. Web Vitals come from the page actually loading.

playwright · cdp

SSRF-hardened fetching

Every target URL and every redirect is checked against private, loopback and cloud-metadata ranges before a byte is fetched.

ssrf guard

Refresh-safe async scans

Scans run on a Redis-backed job queue. Close the tab, lose Wi-Fi, come back later — the audit keeps going.

redis · arq

Honest about blocked sites

If a Cloudflare or bot-protection challenge answers instead of your site, the scan stops and says so — it never scores a challenge page.

challenge detection

Provider-agnostic AI

Fix generation works with Claude, OpenAI, Gemini and more. If a model fails, the scan still completes — AI never blocks a report.

graceful fallback

Export the whole audit

Every finding, AI fix, code snippet, llms.txt and JSON-LD suggestion ships in the PDF — with CSV and JSON exports for your own tooling.

pdf · csv · json

Who it’s for

One scan. Two very different readers.

The same audit becomes a branded client deliverable or a developer’s bug list — depending on who opens it.

For agencies

Reports clients actually read.

  • White-label PDFYour logo and colours, 100% of the way
  • Scheduled re-scansWeekly or monthly, per client
  • Audit recordsEvery client scan kept, one-click re-audit
  • AI summaryPlain English your clients understand
BugViso for agencies

For developers

Catch it before your users do.

  • Hydration hunterReact / Next.js server–client mismatches
  • Runtime errorsConsole, network and broken assets
  • AI code fixesWritten from your real markup and selectors
  • ExportsPDF, CSV and JSON for your own tooling
BugViso for developers

Pricing

Pay per report, or save with a plan.

Your first full report is free. After that, pick one-off scans or a monthly plan that saves up to 74%.

Pay as you go

Single audit & report

$1.49/ report

  • AI code fixes, SEO rewrites & GEO fixes
  • Full multi-engine site & technical SEO crawl
  • Core Web Vitals & performance lab metrics
  • AI crawler access (GPTBot, ClaudeBot) & llms.txt
  • WCAG 2.1 AA, security & privacy audits
  • Executive PDF report & prioritised fix list
Best value

Developer & agency

Monthly plans

$29/ month

From $0.97 per scan · save up to 74%

  • AI code, SEO & GEO fixes in every report
  • 30 to 500 scans every month
  • Scheduled weekly or monthly re-scans
  • 100% white-label PDF reports (Agency)
  • 90-day to 1-year audit history
  • Priority developer support
  • Unused scans roll over for up to 60 days (capped at 2×)
Compare all plans

Find what’s broken before your users do.

Paste a domain. In about five minutes you’ll know exactly what to fix first — and have AI-written code to do it.