Standards-cited · evidence-backed · nothing installed

Your site is quietly broken.
See exactly where in 60 seconds.

Paste a URL. DevOpsNL audits it like a QA engineer who doesn't get bored: dead buttons, forms with no submit path, exposed secrets, mobile layouts that fall apart, missing privacy consent, pages search engines cannot find. You get a report card graded across eight dimensions.

  • Read-only GET requests only
  • Every finding shipped with evidence
  • First audit free, no account

~60s

from URL to a graded verdict

35+

detectors across 8 categories

Read-only

on any URL you don't own

What it catches

The bugs your users hit and never report.

Evidence-backed detectors across eight graded classes. Each finding carries a DOM selector, a captured request, or a screenshot, and names the exact standard it breaks. Proof, not opinions.

Functional

  • Dead call-to-action buttons
  • Forms with no submit path
  • Broken links (404/500)
  • Broken images
  • Console errors on load
  • Missing favicon or custom 404 page

Security

  • Exposed API keys in client JS
  • Publicly readable config files
  • Missing or weak security headers
  • CSP / clickjacking / mixed content
  • security.txt validation (RFC 9116)

Privacy

  • Trackers firing before consent
  • Non-essential cookies on cold load
  • Missing consent mechanism
  • No privacy policy link

Accessibility

  • Images without alt text
  • Unnamed interactive controls
  • Low-contrast text
  • Missing focus indicators

UX friction

  • Viewport overflow on mobile
  • Tap targets too small
  • Unreadably tiny text

Performance

  • Slow FCP and LCP
  • Layout shift while loading
  • Oversized bundles & unoptimized images

SEO

  • Missing or placeholder page title
  • No meta description
  • Accidental noindex on a live page
  • Missing canonical URL
  • No structured data (JSON-LD)
  • robots.txt blocking the whole site

Design

  • Buttons styled inconsistently
  • Text colours off a shared palette
  • No print stylesheet or poor readability

How we audit

Held to the standards a real audit firm uses.

DevOpsNL doesn't invent rules. It audits against published standards, and every finding names the standard or best practice it is based on — including which checks could not run.

OWASP ASVS 4.0.3

The Application Security Verification Standard: the security requirements a pentest firm checks against.

WCAG 2.2, Level A and AA

The accessibility success criteria that procurement, legal, and real users require.

GDPR & cookie law

Trackers and non-essential cookies are measured on a cold load with nothing clicked — the moment ePrivacy Art. 5(3) actually governs.

Core Web Vitals

LCP, CLS and Total Blocking Time measured on an emulated phone over Slow 4G, plus real-visitor LCP, INP and CLS from the Chrome UX Report where the origin has enough traffic.

OWASP Secure Headers

The response-header baseline that closes off whole classes of attacks.

Nielsen Norman heuristics

The ten usability principles behind every UX finding, not vibes.

Ranked remediation

Fix directions ranked worst first, so you know what to fix and in what order.

How it works

URL in. Evidence out. Safe on production.

1

Paste a public URL

Any live page, yours or a competitor's. No account, no script tag, no browser extension.

2

It audits, as deep as you allow

Quick runs 35+ checks on any public page in about a minute. Deep crawls up to 50 pages and adds sitemap validation, responsive testing, and form UX analysis. Deepest adds infrastructure security, keyboard navigation, and dependency scanning.

3

Shareable report card

A graded report headlined by the most damaging finding, every issue backed by evidence and cited to the standard it breaks.

Pricing

Start free. Go deeper when the domain is yours.

Quick is free and read-only on any public URL. Deep adds authenticated coverage. Deepest adds governed active workflow testing.

Quick

Free

€0/ audit

Zero credentials. Zero signup.

  • Single-page audit, 35+ detectors
  • Headline finding + top issues, evidence-backed
  • Score, grade, and full severity counts
  • Shareable, screenshot-worthy report
Run free audit
€9.99 · 5 AUDITS

Deep

€9.99/ 5 scans

Beta price, one-off. No subscription. Invite-only.

  • Crawls up to 50 pages automatically
  • Sitemap validation & internal link analysis
  • Dark mode, responsive & form UX testing
  • Structured data & hreflang checks
  • Every finding ranked, with evidence
  • SARIF / JSON export for CI integration
Join the waitlist
€19.99 · 5 AUDITS

Deepest

€19.99/ 5 scans

Beta price, one-off. No subscription. Invite-only.

  • Includes every Deep capability
  • SSL/TLS certificate & cipher analysis
  • Server hardening: info disclosure, HTTP methods
  • Subdomain reconnaissance & exposed paths
  • Email security: SPF, DMARC & DKIM audit
  • Token/JWT exposure & dependency/CVE scanning
  • Keyboard navigation & focus trap testing
  • Active form testing: XSS & injection payloads
  • Stops before charges or destruction
Join the waitlist

Enterprise

Testing scoped to your stack, on demand.

  • Custom audit scope and schedule
  • Deeper and more aggressive testing
  • Dedicated support
  • Custom integrations
Talk to us

FEATURE COMPARISON

What each tier actually tests

Quick gives you a snapshot. Deep gives you coverage. Deepest gives you a full infrastructure security audit.

FeatureQuick€0DeepClosed betaDeepestClosed beta
Scope
Pages scanned1≤ 50≤ 50
Automatic crawling
Detection & Analysis
Functional issues
Accessibility (WCAG)
Focus indicators
Keyboard navigation testing
SEO analysis
Sitemap & structured data
UX issues
Dark mode & responsive testing
Form UX (labels, autocomplete)
Design consistency
Performance (lab)
Resource & image optimization
Real-user field data (CrUX)
Privacy / GDPR
Security & Hardening
Security headers
CSP & clickjacking analysis
security.txt validation (RFC 9116)
Exposed secrets scan
Sensitive file detection
SSL/TLS & certificate audit
Server hardening analysis
HTTP method testing
Subdomain reconnaissance
Exposed path discovery
Email security (SPF/DMARC)
DKIM record validation
Subresource integrity
Active form testing (XSS/SQLi)
Token/JWT exposure scan
Dependency/CVE scanning
Reporting
Score & grade
Evidence per finding
Shareable report
Prioritised remediation plan
SARIF / JSON export

Why it's safe to point at production

It never writes to a site you don't own.

Free audits are read-only

A Quick audit loads a page and reads it. It never logs in, never fills a form, and never submits anything — it only requests what a visitor's browser would.

Crawling stays within the rules

Multi-page audits honour robots.txt, including Crawl-delay, and are limited to one domain. Deep and Deepest are in closed beta and only run on domains we've released them for.

It says what it could not test

If a check cannot run on your site, the report marks that category as not assessed and leaves it out of the grade. A blocked check never turns into a passing score.

Secrets stay masked

If DevOpsNL finds an exposed key, the shared report shows a redacted proof. The raw secret never appears in anything distributable.

Closed beta

Get Deep and Deepest first

The multi-page and full-workflow audits for a domain you own are in closed beta. Join the waitlist and we'll email you an invite.

Prefer to look first? Run free audit, no account needed.