Skip to main content
A100 CHALLENGEScore a perfect 100 on your Deepest audit and get your €19.99 backFastest 100 of the year wins €777

Standards-cited · evidence-backed · nothing installed

Your site is quietly broken.
See exactly where in 60 seconds.

Paste a URL. DevOpsNL audits it like a QA engineer who doesn't get bored: dead buttons, forms with no submit path, exposed secrets, mobile layouts that fall apart, missing privacy consent, pages search engines cannot find. You get a report card graded across eight dimensions.

  • Read-only GET requests only
  • Every finding shipped with evidence
  • First audit free, no account

~60s

from URL to a graded verdict

35+

detectors across 8 categories

Read-only

on any URL you don't own

The 26 sites audited so far average 83 out of 100. On security alone they average 75. Where does yours land?

What it catches

The bugs your users hit and never report.

Evidence-backed detectors across eight graded classes. Each finding carries a DOM selector, a captured request, or a screenshot, and names the exact standard it breaks. Proof, not opinions.

Functional

  • Dead call-to-action buttons
  • Forms with no submit path
  • Broken links (404/500)
  • Broken images
  • Console errors on load
  • Missing favicon or custom 404 page

Security

  • Exposed API keys in client JS
  • Publicly readable config files
  • Missing or weak security headers
  • CSP / clickjacking / mixed content
  • security.txt validation (RFC 9116)

Privacy

  • Trackers firing before consent
  • Non-essential cookies on cold load
  • Missing consent mechanism
  • No privacy policy link

Accessibility

  • Images without alt text
  • Unnamed interactive controls
  • Low-contrast text
  • Missing focus indicators

UX friction

  • Viewport overflow on mobile
  • Tap targets too small
  • Unreadably tiny text

Performance

  • Slow FCP and LCP
  • Layout shift while loading
  • Oversized bundles & unoptimized images

SEO

  • Missing or placeholder page title
  • No meta description
  • Accidental noindex on a live page
  • Missing canonical URL
  • No structured data (JSON-LD)
  • robots.txt blocking the whole site

Design

  • Buttons styled inconsistently
  • Text colours off a shared palette
  • No print stylesheet or poor readability

How we audit

Held to the standards a real audit firm uses.

DevOpsNL doesn't invent rules. It audits against published standards, and every finding names the standard or best practice it is based on, including which checks could not run.

OWASP ASVS 5.0.0

The Application Security Verification Standard: the security requirements a pentest firm checks against.

WCAG 2.2, Level A and AA

The accessibility success criteria that procurement, legal, and real users require.

GDPR & cookie law

Trackers and non-essential cookies are measured on a cold load with nothing clicked: the moment ePrivacy Art. 5(3) actually governs.

Core Web Vitals

LCP, CLS and Total Blocking Time measured on an emulated phone over Slow 4G, plus real-visitor LCP, INP and CLS from the Chrome UX Report where the origin has enough traffic.

OWASP Secure Headers

The response-header baseline that closes off whole classes of attacks.

Nielsen Norman heuristics

The ten usability principles behind every UX finding, not vibes.

Ranked remediation

Fix directions ranked worst first, so you know what to fix and in what order.

How it works

URL in. Evidence out. Safe on production.

1

Paste a public URL

Any live page, yours or a competitor's. No account, no script tag, no browser extension.

2

It audits, as deep as you allow

Quick runs 35+ checks on any public page in about a minute. Deep crawls up to 50 pages and adds sitemap validation, responsive testing, and form UX analysis. Deepest adds infrastructure security, keyboard navigation, and dependency scanning.

3

Shareable report card

A graded report headlined by the most damaging finding, every issue backed by evidence and cited to the standard it breaks.

Pricing

Start free. Go deeper when the domain is yours.

Quick is free and read-only on any public URL. Deep adds authenticated coverage. Deepest adds governed active workflow testing.

Quick

Free

€0/ audit

Zero credentials. Zero signup.

  • Single-page audit, 40+ detectors
  • JavaScript & WebSocket security analysis
  • Score, grade, and full severity counts
  • Shareable, screenshot-worthy report
Run free audit
€9.99 · 5 AUDITS

Deep

€9.99/ 5 scans

Beta price, one-off. No subscription. Invite-only.

  • Crawls up to 50 pages automatically
  • Open redirect vulnerability detection
  • Dark mode, responsive & form UX testing
  • Structured data & hreflang checks
  • Every finding ranked, with evidence
  • SARIF / JSON export for CI integration
  • Deep SEO & UX analysis
Join the waitlist
€19.99 · 5 AUDITS

Deepest

€19.99/ 5 scans

Beta price, one-off. No subscription. Invite-only.

  • Includes every Deep capability
  • SSL/TLS certificate & cipher analysis
  • Subdomain takeover detection (17 platforms)
  • SSRF & host header injection scanning
  • Email security: SPF, DMARC & DKIM audit
  • Token/JWT exposure & dependency/CVE scanning
  • Keyboard navigation & focus trap testing
  • Active form testing: XSS & injection payloads
  • Server hardening & open port scanning
  • Critical infrastructure security checks
  • A100 Challenge: score 100 within your 5 credits → full refund + Hall of Fame listing
Join the waitlist

Enterprise

Testing scoped to your stack, on demand.

  • Custom audit scope and schedule
  • Deeper and more aggressive testing
  • Dedicated support
  • Custom integrations
Talk to us