Config
What each scan module and plan covers, in plain language.
When you pick modules (or a named scan wrapper), you are choosing what kinds of problems the hosted audit looks for. You do not need to know how the crawler works — use this table to decide what to turn on.
| Module | Looks for | In plain English |
|---|---|---|
| seo | Page title, meta description, H1 headings | Search engines and browser tabs need a clear title and short description. We flag missing, duplicate, or empty ones so pages are easier to find and share. |
| links | Broken and redirected links on the page | We follow links on each crawled page and report ones that 404 or bounce unexpectedly — the kind of dead ends that frustrate visitors and look unfinished. |
| accessibility | Image alt text and form labels (baseline — not a WCAG certificate) | Basic checks for screen-reader and keyboard basics: images without descriptions, inputs without labels. This is a smoke pass, not a full accessibility audit or legal certification. |
| security | HTTPS / TLS and related passive signals | Confirms the site is served over HTTPS and notes common configuration gaps we can see without attacking the server. Not a penetration test. |
| mobile | Viewport and mobile-friendly signals | Checks that pages declare how they should look on phones. Missing viewport settings often make a site feel broken on mobile. |
| social | Open Graph / social preview tags | When someone pastes your URL in Slack, LinkedIn, or X, these tags control the title, blurb, and image. We flag missing or incomplete previews. |
| performance | Fetch time and page size (not Lighthouse) | A lightweight timing of how long the page took to download and how large the HTML is. Useful as a relative signal — not a full Core Web Vitals lab report. |
Plans set how deep the crawl goes and which report extras you get. The CLI `--tier` flag uses the same plan IDs (`launch`, `essential`, `team`, `engineering`, `security-pro`).
| Plan | Best for | What you get |
|---|---|---|
| Launch | A focused website sanitation check | Broad, lightweight checks (up to 75 pages): broken links, SEO basics, HTTPS, and accessibility basics. No Application Map, no command-line API access. Use this to see if the product is a fit before buying deeper coverage. |
| Essential | Understanding what your site contains | Multi-page crawl with an Application Map (routes, forms, controls), Jira-ready findings, plus mobile and social signals. No Test Coverage Review bundle. |
| Team | Turning the map into QA work | Everything in Essential, plus command-line tools to inventory tests and Test Coverage Review (pages/routes, Application Map buttons and forms, unit/component files compared to the live crawl). Includes AI fix suggestions for reported issues. |
| Engineering | Going deeper into how the app behaves | Everything in Team, plus safe click-path / flow checks and manual drafts for uncovered pages and key controls (snippets to review). Still not credentialed journeys or a pentest. |
| Security Pro | Website QA plus a separate security assessment | Team-depth website QA, then a separate network / API assessment: DNS ownership proof, network scan exports, and optional authenticated session probe with a QA test login. Contact us to start; not a substitute for a full pen test. |
Safe-active checks (Engineering and above) never send injection payloads or submit forms to other websites. When those checks run, findings and the Jira CSV may include a `safe-active` label so your team can tell them apart from passive page reads.