For agencies
Reports clients actually read.
- White-label PDFYour logo and colours, 100% of the way
- Scheduled re-scansWeekly or monthly, per client
- Audit recordsEvery client scan kept, one-click re-audit
- AI summaryPlain English your clients understand
25 engines audit SEO, AI search readiness, performance, security and accessibility across your whole site in a real browser — then AI writes the code fixes, SEO rewrites and GEO fixes for your exact site — ranked by impact, in a branded PDF.
bugviso.com
42 pages scanned · 1m 48s
How a scan runs
Reads sitemap.xml and robots.txt, then walks same-host links breadth-first to map the whole site — not just the homepage.
sitemap · bfs · depth-limited
Each page loads in real headless Chromium on desktop and mobile, throttled like a mid-range phone on a slow network.
chromium · 4× cpu · 3g
25 engines inspect every page: axe-core accessibility, Web Vitals, TLS, SimHash duplicates, SSIM visual diffs and AI-bot probes.
74 checks per page
Findings are scored, ranked by impact and turned into copy-paste fixes — then packaged into a branded PDF you can hand to anyone.
playbook · ai fixes · pdf
The engine room
Every engine runs on every scan — no add-ons, no five tools to stitch together. Findings from all of them land in one scored, prioritised report.
Discipline 01 / 07
12
checks · 4 engines
AI crawler accessflagship
Makes sure AI bots aren’t blocked by robots.txt or your firewall.
Content AI bots can seenew
Compares what bots receive before JavaScript runs with what visitors see.
llms.txt fileAInew
Checks your guide file for AI tools — and AI drafts one if it’s missing.
Brand identity & citationsnew
Checks the signals that help AI recognise your brand and quote you.
Discipline 02 / 07
18
checks · 6 engines
Technical SEO
Structured data, canonical and language tags, headings and image alt text.
Keyword focusnew
Finds each page’s main keyword and checks it’s used in the right places.
Duplicate contentnew
Finds pages that are copies or near-copies of each other.
Internal linksnew
Maps how your pages link together and finds pages nothing links to.
Backlinksnew
Reviews the sites that link to you and flags spammy links.
Titles & meta tags
Page titles, descriptions, social previews and heading order.
Discipline 03 / 07
6
checks · 2 engines
Core Web Vitals
Google’s loading, responsiveness and layout-stability scores, measured live.
Slow-network testing
Reloads pages on slow mobile connections and finds unused code.
Discipline 04 / 07
6
checks · 2 engines
HTTPS & security headers
Your certificate, HTTPS setup and the headers that protect visitors.
Cookie consent (GDPR / CCPA)
Flags tracking cookies and pixels that load before visitors agree.
Discipline 05 / 07
6
checks · 2 engines
Accessibility (WCAG 2.1 AA)
Barriers for keyboard and screen-reader users, ranked by impact.
Mobile experience
Loads each page as a phone would and checks it’s easy to read and tap.
Discipline 06 / 07
15
checks · 5 engines
Visual layout
Screenshots your pages and spots broken or shifted layouts.
React / Next.js mismatches
Catches pages where the server and browser render different content.
JavaScript errors
Every script error, with the file and line it came from.
Failed requests
Files that fail to load, or load over an insecure connection.
Broken links & images
Tests every internal and external link and image.
Discipline 07 / 07
11
checks · 4 engines
Whole-site crawl
Finds your pages through the sitemap and links, then checks each one.
Prioritised fix listAI
Turns every finding into a do-this-next list with AI-written, copy-paste fixes.
PDF report
A branded report with your score, grade and every fix, ready to share.
Email deliverynew
Sends the report to your inbox as soon as the scan finishes.
Discipline 01 / 07
AI search readiness
12
checks · 4 engines
Findings are cheap. Fixes ship.
The remediation engine pairs each problem with copy-paste markup, headers, config or commands. Then AI rewrites every fix with your site’s real code and content — ready to paste, not a generic tip.
Three sets of fixes, written from your pages’ real code and copy — ready to paste.
AI code fixes
For developers
AI SEO
For search engines
AI GEO
For AI answers
Plus a plain-English summary that tells you what to fix first and which wins are quick.
All in your PDF report
Real fixes from the remediation library
06 categories
AI Search Readiness
01 / 06Over 70% of modern sites unintentionally block AI crawlers via Cloudflare Managed Rules (WAF 403) or render empty SPA shells without an llms.txt knowledge manifest.
# robots.txt looks fine, BUT Cloudflare WAF silently blocks AI bots with 403:
# CF-WAF Rule: Block Automated Traffic (Managed Challenge) -> GPTBot 403 Forbidden!
# Result: 0 citations in ChatGPT Search & Perplexity# 1. /llms.txt - Standard Generative Engine Manifest
# https://yourdomain.com/llms.txt
# Core Technical Architecture
> Modern high-performance web platform audited by BugViso.
## Primary Documentation Clusters
- [API Reference](/docs/api): REST endpoints & webhooks
- [System Architecture](/docs/architecture): Component pipelines
# 2. Cloudflare WAF Custom Rule (Expression):
# (cf.client.bot and http.user_agent contains "GPTBot") or
# (http.user_agent contains "ClaudeBot") -> Action: Skip (Bypass WAF)SEO & Content Intelligence
02 / 06Search engines and AI models rely on Schema.org structured data to verify company identities, products, and author authority. Missing schema reduces rich snippet CTR.
<!-- Missing structured data -->
<h1>Core Web Vitals Guide</h1><script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "TechArticle",
"headline": "Core Web Vitals Guide",
"author": { "@type": "Person", "name": "Technical Lead" },
"datePublished": "2026-09-01",
"publisher": { "@type": "Organization", "name": "BugViso" }
}
</script>Performance & Core Web Vitals
03 / 06Heavy render-blocking hero images delay LCP (>2.5s), while long JavaScript tasks freeze the main thread, causing severe INP (Interaction to Next Paint) latency.
// Unoptimized image loading
<img src="/hero.png" />// 1. High-priority LCP hero image with eager decoding
<img
src="/hero.webp"
fetchpriority="high"
loading="eager"
decoding="async"
/>
// 2. Yield to browser main thread during heavy calculations
await (window.scheduler?.yield?.() || new Promise(r => setTimeout(r, 0)));Security & Privacy
04 / 06Missing HSTS, Content Security Policy (CSP), or X-Frame-Options leaves web applications vulnerable to clickjacking, MIME sniffing, and mixed-content blocking.
// Server responses without defensive security headers
app.get('/', (req, res) => res.send('OK'));// Defensive security headers middleware
const securityHeaders = {
"Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
"X-Content-Type-Options": "nosniff",
"X-Frame-Options": "SAMEORIGIN",
"Referrer-Policy": "strict-origin-when-cross-origin",
"Content-Security-Policy": "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'"
};Accessibility & Mobile
05 / 06Icon-only action buttons without accessible names cause automatic screen-reader failure and WCAG 2.1 AA violations.
// Inaccessible icon button
<button onClick={handleDelete}>
<TrashIcon />
</button>// WCAG 2.1 AA Compliant with keyboard focus ring & sr-only label
<button
onClick={handleDelete}
aria-label="Delete audit report"
className="focus-visible:ring-2 focus-visible:ring-violet-500 outline-none"
>
<TrashIcon aria-hidden="true" />
<span className="sr-only">Delete audit report</span>
</button>Visual & Code QA
06 / 06Minified React errors (#418 / #423 / #425) occur when server-rendered HTML differs from client-rendered state (e.g. timestamps, localStorage, window dimensions).
// Causes server/client mismatch crash
function Timestamp() {
return <div>Rendered at: {new Date().toLocaleTimeString()}</div>;
}// Solution A: suppressHydrationWarning for dynamic text
<time suppressHydrationWarning>{timeString}</time>
// Solution B: Client-only mounting guard
const [mounted, setMounted] = useState(false);
useEffect(() => setMounted(true), []);
if (!mounted) return <SkeletonLoader />;From finding to fixed
Critical, high and quick-win tiers with effort estimates, so the first fix is always the one that matters most.
AI fixes, code snippets, llms.txt and JSON-LD all land in the PDF, so whoever implements them has everything in one file.
Every scan is kept in your audit records. Re-run a domain after shipping to confirm the fixes landed and the score moved.
AI search readiness · GEO
robots.txt can say yes while your CDN says no. BugViso probes with real AI-crawler user agents, compares server HTML against the hydrated DOM, validates llms.txt and scores how citable your content is. Then AI drafts the llms.txt and structured data to fix it.
How the GEO engines workAI crawler probe
bugviso.com
| User agent | robots.txt | Live edge |
|---|---|---|
| GPTBot | allowed | 403 · WAF |
| ClaudeBot | allowed | 200 OK |
| PerplexityBot | allowed | 200 OK |
| Google-Extended | disallowed | opted out |
SSR parity
4%
empty SPA shell
llms.txt
404
not published
Citability
58
of 100
AI fix → add a WAF skip rule for verified AI bots, prerender the SPA and publish /llms.txt
Under the hood
The same pipeline powers the free scan, scheduled re-scans and every report — engineered for accuracy first, then speed.
Every page renders in headless Chromium on desktop and mobile, with CPU and network throttling over CDP — not a static HTML fetch. Web Vitals come from the page actually loading.
playwright · cdp
Every target URL and every redirect is checked against private, loopback and cloud-metadata ranges before a byte is fetched.
ssrf guard
Scans run on a Redis-backed job queue. Close the tab, lose Wi-Fi, come back later — the audit keeps going.
redis · arq
If a Cloudflare or bot-protection challenge answers instead of your site, the scan stops and says so — it never scores a challenge page.
challenge detection
Fix generation works with Claude, OpenAI, Gemini and more. If a model fails, the scan still completes — AI never blocks a report.
graceful fallback
Every finding, AI fix, code snippet, llms.txt and JSON-LD suggestion ships in the PDF — with CSV and JSON exports for your own tooling.
pdf · csv · json
Who it’s for
The same audit becomes a branded client deliverable or a developer’s bug list — depending on who opens it.
For agencies
For developers
Pricing
Your first full report is free. After that, pick one-off scans or a monthly plan that saves up to 74%.
Pay as you go
$1.49/ report
Developer & agency
$29/ month
From $0.97 per scan · save up to 74%
Paste a domain. In about five minutes you’ll know exactly what to fix first — and have AI-written code to do it.