Config

Attribute cheat sheet

What each scan module and plan covers, in plain language.

When you pick modules (or a named scan wrapper), you are choosing what kinds of problems the hosted audit looks for. You do not need to know how the crawler works — use this table to decide what to turn on.

ModuleLooks forIn plain English
seoPage title, meta description, H1 headingsSearch engines and browser tabs need a clear title and short description. We flag missing, duplicate, or empty ones so pages are easier to find and share.
linksBroken and redirected links on the pageWe follow links on each crawled page and report ones that 404 or bounce unexpectedly — the kind of dead ends that frustrate visitors and look unfinished.
accessibilityImage alt text and form labels (baseline — not a WCAG certificate)Basic checks for screen-reader and keyboard basics: images without descriptions, inputs without labels. This is a smoke pass, not a full accessibility audit or legal certification.
securityHTTPS / TLS and related passive signalsConfirms the site is served over HTTPS and notes common configuration gaps we can see without attacking the server. Not a penetration test.
mobileViewport and mobile-friendly signalsChecks that pages declare how they should look on phones. Missing viewport settings often make a site feel broken on mobile.
socialOpen Graph / social preview tagsWhen someone pastes your URL in Slack, LinkedIn, or X, these tags control the title, blurb, and image. We flag missing or incomplete previews.
performanceFetch time and page size (not Lighthouse)A lightweight timing of how long the page took to download and how large the HTML is. Useful as a relative signal — not a full Core Web Vitals lab report.

Plans set how deep the crawl goes and which report extras you get. The CLI `--tier` flag uses the same plan IDs (`launch`, `essential`, `team`, `engineering`, `security-pro`).

PlanBest forWhat you get
LaunchA focused website sanitation checkBroad, lightweight checks (up to 75 pages): broken links, SEO basics, HTTPS, and accessibility basics. No Application Map, no command-line API access. Use this to see if the product is a fit before buying deeper coverage.
EssentialUnderstanding what your site containsMulti-page crawl with an Application Map (routes, forms, controls), Jira-ready findings, plus mobile and social signals. No Test Coverage Review bundle.
TeamTurning the map into QA workEverything in Essential, plus command-line tools to inventory tests and Test Coverage Review (pages/routes, Application Map buttons and forms, unit/component files compared to the live crawl). Includes AI fix suggestions for reported issues.
EngineeringGoing deeper into how the app behavesEverything in Team, plus safe click-path / flow checks and manual drafts for uncovered pages and key controls (snippets to review). Still not credentialed journeys or a pentest.
Security ProWebsite QA plus a separate security assessmentTeam-depth website QA, then a separate network / API assessment: DNS ownership proof, network scan exports, and optional authenticated session probe with a QA test login. Contact us to start; not a substitute for a full pen test.

Safe-active checks (Engineering and above) never send injection payloads or submit forms to other websites. When those checks run, findings and the Jira CSV may include a `safe-active` label so your team can tell them apart from passive page reads.