Standards-cited · evidence-backed · nothing installed
Your site is quietly broken.
See exactly where in 60 seconds.
Paste a URL. DevOpsNL audits it like a QA engineer who doesn't get bored: dead buttons, forms with no submit path, exposed secrets, mobile layouts that fall apart, missing privacy consent, pages search engines cannot find. You get a report card graded across eight dimensions.
- Read-only GET requests only
- Every finding shipped with evidence
- First audit free, no account
~60s
from URL to a graded verdict
35+
detectors across 8 categories
Read-only
on any URL you don't own
What it catches
The bugs your users hit and never report.
Evidence-backed detectors across eight graded classes. Each finding carries a DOM selector, a captured request, or a screenshot, and names the exact standard it breaks. Proof, not opinions.
Functional
- Dead call-to-action buttons
- Forms with no submit path
- Broken links (404/500)
- Broken images
- Console errors on load
- Missing favicon or custom 404 page
Security
- Exposed API keys in client JS
- Publicly readable config files
- Missing or weak security headers
- CSP / clickjacking / mixed content
- security.txt validation (RFC 9116)
Privacy
- Trackers firing before consent
- Non-essential cookies on cold load
- Missing consent mechanism
- No privacy policy link
Accessibility
- Images without alt text
- Unnamed interactive controls
- Low-contrast text
- Missing focus indicators
UX friction
- Viewport overflow on mobile
- Tap targets too small
- Unreadably tiny text
Performance
- Slow FCP and LCP
- Layout shift while loading
- Oversized bundles & unoptimized images
SEO
- Missing or placeholder page title
- No meta description
- Accidental noindex on a live page
- Missing canonical URL
- No structured data (JSON-LD)
- robots.txt blocking the whole site
Design
- Buttons styled inconsistently
- Text colours off a shared palette
- No print stylesheet or poor readability
How we audit
Held to the standards a real audit firm uses.
DevOpsNL doesn't invent rules. It audits against published standards, and every finding names the standard or best practice it is based on — including which checks could not run.
OWASP ASVS 4.0.3
The Application Security Verification Standard: the security requirements a pentest firm checks against.
WCAG 2.2, Level A and AA
The accessibility success criteria that procurement, legal, and real users require.
GDPR & cookie law
Trackers and non-essential cookies are measured on a cold load with nothing clicked — the moment ePrivacy Art. 5(3) actually governs.
Core Web Vitals
LCP, CLS and Total Blocking Time measured on an emulated phone over Slow 4G, plus real-visitor LCP, INP and CLS from the Chrome UX Report where the origin has enough traffic.
OWASP Secure Headers
The response-header baseline that closes off whole classes of attacks.
Nielsen Norman heuristics
The ten usability principles behind every UX finding, not vibes.
Ranked remediation
Fix directions ranked worst first, so you know what to fix and in what order.
How it works
URL in. Evidence out. Safe on production.
Paste a public URL
Any live page, yours or a competitor's. No account, no script tag, no browser extension.
It audits, as deep as you allow
Quick runs 35+ checks on any public page in about a minute. Deep crawls up to 50 pages and adds sitemap validation, responsive testing, and form UX analysis. Deepest adds infrastructure security, keyboard navigation, and dependency scanning.
Shareable report card
A graded report headlined by the most damaging finding, every issue backed by evidence and cited to the standard it breaks.
Pricing
Start free. Go deeper when the domain is yours.
Quick is free and read-only on any public URL. Deep adds authenticated coverage. Deepest adds governed active workflow testing.
Quick
Free€0/ audit
Zero credentials. Zero signup.
- Single-page audit, 35+ detectors
- Headline finding + top issues, evidence-backed
- Score, grade, and full severity counts
- Shareable, screenshot-worthy report
Deep
€9.99/ 5 scans
Beta price, one-off. No subscription. Invite-only.
- Crawls up to 50 pages automatically
- Sitemap validation & internal link analysis
- Dark mode, responsive & form UX testing
- Structured data & hreflang checks
- Every finding ranked, with evidence
- SARIF / JSON export for CI integration
Deepest
€19.99/ 5 scans
Beta price, one-off. No subscription. Invite-only.
- Includes every Deep capability
- SSL/TLS certificate & cipher analysis
- Server hardening: info disclosure, HTTP methods
- Subdomain reconnaissance & exposed paths
- Email security: SPF, DMARC & DKIM audit
- Token/JWT exposure & dependency/CVE scanning
- Keyboard navigation & focus trap testing
- Active form testing: XSS & injection payloads
- Stops before charges or destruction
Enterprise
Testing scoped to your stack, on demand.
- Custom audit scope and schedule
- Deeper and more aggressive testing
- Dedicated support
- Custom integrations
FEATURE COMPARISON
What each tier actually tests
Quick gives you a snapshot. Deep gives you coverage. Deepest gives you a full infrastructure security audit.
| Feature | Quick€0 | DeepClosed beta | DeepestClosed beta |
|---|---|---|---|
| Scope | |||
| Pages scanned | 1 | ≤ 50 | ≤ 50 |
| Automatic crawling | — | ||
| Detection & Analysis | |||
| Functional issues | |||
| Accessibility (WCAG) | |||
| Focus indicators | |||
| Keyboard navigation testing | — | — | |
| SEO analysis | |||
| Sitemap & structured data | — | ||
| UX issues | |||
| Dark mode & responsive testing | — | ||
| Form UX (labels, autocomplete) | — | ||
| Design consistency | |||
| Performance (lab) | |||
| Resource & image optimization | |||
| Real-user field data (CrUX) | |||
| Privacy / GDPR | |||
| Security & Hardening | |||
| Security headers | |||
| CSP & clickjacking analysis | |||
| security.txt validation (RFC 9116) | |||
| Exposed secrets scan | |||
| Sensitive file detection | |||
| SSL/TLS & certificate audit | — | — | |
| Server hardening analysis | — | — | |
| HTTP method testing | — | — | |
| Subdomain reconnaissance | — | — | |
| Exposed path discovery | — | — | |
| Email security (SPF/DMARC) | — | — | |
| DKIM record validation | — | — | |
| Subresource integrity | — | — | |
| Active form testing (XSS/SQLi) | — | — | |
| Token/JWT exposure scan | — | — | |
| Dependency/CVE scanning | — | — | |
| Reporting | |||
| Score & grade | |||
| Evidence per finding | |||
| Shareable report | |||
| Prioritised remediation plan | — | — | |
| SARIF / JSON export | — | ||
Why it's safe to point at production
It never writes to a site you don't own.
Free audits are read-only
A Quick audit loads a page and reads it. It never logs in, never fills a form, and never submits anything — it only requests what a visitor's browser would.
Crawling stays within the rules
Multi-page audits honour robots.txt, including Crawl-delay, and are limited to one domain. Deep and Deepest are in closed beta and only run on domains we've released them for.
It says what it could not test
If a check cannot run on your site, the report marks that category as not assessed and leaves it out of the grade. A blocked check never turns into a passing score.
Secrets stay masked
If DevOpsNL finds an exposed key, the shared report shows a redacted proof. The raw secret never appears in anything distributable.
Closed beta
Get Deep and Deepest first
The multi-page and full-workflow audits for a domain you own are in closed beta. Join the waitlist and we'll email you an invite.
Prefer to look first? Run free audit, no account needed.