986 deterministic rules · Real browser · No AI in the score
Paste your address. We open your site in a real browser, run up to 986 individual checks over it, and hand back a score out of 100 with a plain-English list of what to fix first — and why it matters.
One scan
Every count below is read from the rule registry when this page is built, so it cannot drift from the product. AI visibility, answer engines and AI agents are three of the 11 — 228 checks between them — and have a section of their own below.
SEO
Whether search engines can index you at all — robots directives, canonicals, hreflang, pagination — and whether your titles, descriptions and headings give them anything to work with. It also checks the card your link turns into when someone pastes it into LinkedIn, Slack or WhatsApp.
WCAG 2.2
Whether someone using a screen reader, a keyboard or larger text can actually use your site. The primary engine runs inside the real browser against your rendered page; a second, independent engine reads the same markup and reports what the first missed.
Schema
Your JSON-LD parsed and expanded to real schema.org types, then checked against what each search feature actually requires — so you find out a recipe card will not appear before you wonder why it never did.
Headers & TLS
The protective headers a browser looks for, graded directive by directive rather than present-or-absent: your content security policy checked source by source, HSTS with its max-age and subdomain coverage, clickjacking protection, mixed content — plus a real TLS handshake against your certificate.
Core Web Vitals
Load speed and layout stability measured live in a real browser against Google's published thresholds — Largest Contentful Paint, Cumulative Layout Shift, First Contentful Paint and Total Blocking Time — and the rest of the rules cover the scripts, caching, images and fonts behind those numbers.
HTML
Markup conformance against the HTML Living Standard, read from the raw response before any browser repairs it. A mis-nested tag or a duplicate id is invisible on screen and permanently wrong in the DOM.
CSS
Your inline styles and up to ten linked stylesheets parsed against the W3C property definitions, then resolved against current browser support — so you learn a valid declaration is unsupported in Safari before your customers do.
Trust
What a cautious buyer checks in four seconds: a contact route they can find, a privacy policy and terms, a published address, a named business — and the patterns that make an honest site read as a scam, like a countdown with nothing behind it or a trust seal that links nowhere.
GEO 100 · AEO 100 · Agentic 28
Whether AI systems can reach you, quote you and operate your site. Three separate questions, three separate scores — see below.
Rules that cannot apply to your page do not run, so the number evaluated is the number relevant to you. The report names every area that ran and every one that did not.
AI visibility
Three different questions hide inside that one, and most sites pass the first and fail the others. 228 checks answer all three separately.
Every AI crawler obeys its own name in your robots.txt, and blocking one does nothing to the others.
So each user-agent token is checked individually — GPTBot, OAI-SearchBot and ChatGPT-User for OpenAI; ClaudeBot, Claude-User and Claude-SearchBot for Claude; PerplexityBot, Google-Extended, Applebot-Extended and the rest, alongside the search and social crawlers. Your llms.txt is checked too, and your robots.txt is resolved the way a crawler resolves it, per RFC 9309 — groups, specificity and Allow overrides — so you learn what your file actually permits rather than what reading it top to bottom suggests.
The one that catches people out: Google-Extended controls whether you can appear in Gemini answers and AI Overviews and has nothing to do with ordinary Google indexing. Allowing one is not allowing the other.
Run this checkBeing crawlable is not the same as being quotable.
What makes a passage liftable and attributable: question-shaped headings, FAQ and how-to markup, semantic landmarks a machine can pick apart, a named author, and publication and modification dates. An answer engine that cannot tell where your answer starts and ends will summarise your competitor instead.
Run this checkFor the software now booking, buying and filling in forms on people's behalf.
Is there a real button an agent can find and read the label of, rather than a div that behaves like one. Are your form fields labelled and your inputs given the right autocomplete tokens. Can it get past your cookie banner. Is anything important behind a hover-only menu it will never trigger.
A site can be perfectly crawlable and still be a dead end for an agent asked to book a table.
Run this checkThe AI Ready badge, at 90 or above. Score 90 or better on AI visibility — the 100 crawler-access checks — and you can display the AI Ready badge on your own site. Below the threshold the badge endpoint returns a refusal instead of an image. A badge that can refuse is the only kind worth displaying.
Real browser
Your page, actually rendered
Core Web Vitals
Measured, not estimated
WCAG 2.2
Live accessibility tree
W3C standards
HTML and CSS conformance
Markup parser
Errors browsers hide
TLS handshake
Certificate and cipher
Baseline support
Works in every browser
Durable history
Scores over time
Typed end to end
No untyped surface
Deterministic
Same page, same score
Why believe the number
475 of the 986 rules can move your score. Every one of them will tell you what it checked, what it found, what it cost you and which published standard says so.
Every status and every point comes from a rule with a fixed weight. An optional model can rephrase an explanation into plainer English; it cannot change a finding, a severity or a number. The report names whether it ran at all.
A WCAG success criterion, the HTML Living Standard, an internet RFC, a schema.org type or published research — named and linked on the rule's own page next to its severity, its confidence tier and its weight. If a finding looks wrong, the argument is with a published standard, not with us.
A rule enforcing a specification and a rule encoding a well-supported heuristic do not carry the same weight, and pretending otherwise is how audit tools lose trust. Each rule declares its tier, and the tier is a multiplier on the points it can move.
impact = importance × confidence — full on a fail, half on a warning, zero on a pass. Each area reports the points it cost you, and those reconcile against 100 minus your score, to the decimal shown. There is no hidden term.
The rules are deterministic: same page, same evidence, same status, same points. The one number that can move between two runs is the live speed measurement — Core Web Vitals are timed in a real browser and carry real variance, which is why the rules behind them are reported separately from the timings.
This site ships the security headers, canonical tags, structured data and crawler access the scanner reports on. It still loses points — our own content-security-policy rule flags an inline-script allowance we have not removed yet. A tool that scores itself perfectly is a tool that grades itself gently.
Every rule has its own page with its weight, its tier and its citation — browse all 986.
Show the result
Add a DNS record or upload a small file — whichever kind of access you have — and three things unlock. Nothing here is required, and nothing is withheld from anyone who skips it.
At websitevalidator.com/report/yourdomain.com — your overall and per-area scores, what each area measures, and when it was measured. It is a real indexable page, so a prospect looking you up can find it. Individual findings are never published: it says you scored 94 on security, not which header you are missing.
A bar, a card, five stars, a small pill, a single-area badge or the AI Ready tick. Copy the HTML or Markdown and paste it in. It shows your current score rather than the score on the day you added it, and links back to your public report. An area badge shows that area's real number under its own name — never the overall score wearing an accessibility label.
Claimed domains are re-scanned in the background once their score is more than a week old, whenever the scan queue is quiet — a visitor's scan is never held up behind one. Every badge and public page carries its measurement date, so a stale number reads as a stale number instead of passing for a current one.
Your domain, your score, the band, your weakest areas listed honestly worst-first, the date, and a link anyone can use to verify it. Downloads as a sharp 1200 × 630 image — the shape a slide, a case study or a LinkedIn post wants.
Verification exists so the badge means something: anyone can scan any address, but only the owner of a domain can publish a score for it. Run a scan to start.
What it costs
Scan first, decide later. The full report is on screen before anything asks you for anything.
No email, no card, nothing to install.
Very busy shared networks hit a separate daily ceiling. Quick scans stay unlimited either way.
One click. Still no card.
Your first scan is not lost when you sign in — the scans from this browser move onto your account.
We keep a one-line record of each scan — the address, the date and the scores — because that is what draws your trend line. The report itself is held for an hour and never written to a database; after that, re-running the scan is the only way to see it again.
Or check one thing
Not every question needs a full audit. Each of these explains what it checks, answers the questions people actually ask about it, and has a box to run it on its own.
There is also a page for every one of the 986 rules — what it checks, its severity, its confidence tier and how it is weighted. Most carry a box to run just that rule against your address; the ones produced by the accessibility and markup engines run only as part of a scan. Browse the library.
Up to 986 deterministic checks across 11 areas — each finding with the evidence that triggered it, the standard behind it, and a fix you can paste.
Run a free scanNo signup. No credit card. Nothing stored but the result.