Complete website intelligence — SEO, security, performance & accessibility
190 checks across four health pillars, transparent scoring, and prioritized recommendations — built for teams that take website health seriously.
Four pillars of website health
Every page crawled, every issue found, every fix explained. Our audit engine covers 10 categories across four health pillars with 190 individual checks.
SEO
89 checks · 6 categoriesSix core categories covering crawlability, indexability, metadata, content quality, internal links, and structured data.
- robots.txt analysis
- Sitemap validation
- Crawl depth monitoring
- Orphan page detection
- Noindex detection
- Canonical analysis
- Duplicate content
- Redirect chains
- Title tag optimization
- Meta description check
- Open Graph tags
- Duplicate metadata
- Thin content detection
- H1/heading hierarchy
- Image alt text
- Word count analysis
- Broken link detection
- Link distribution
- Nofollow audit
- Anchor text analysis
- Schema presence check
- JSON-LD validation
- Rich snippet eligibility
- Schema warnings
Security
22 checks · 1 categoryHTTPS enforcement, mixed content detection, HSTS validation, and Content Security Policy analysis.
- HTTPS enforcement
- Mixed content check
- HSTS validation
- CSP analysis
Performance
38 checks · 1 categoryResponse time checks, page size analysis, compression validation, and image optimization audits.
- Response time check
- Page size analysis
- Compression check
- Image optimization
Accessibility
41 checks · 2 categoriesWCAG compliance checks, contrast analysis, ARIA landmarks, and mobile-first responsive audits.
- Viewport meta check
- Content width analysis
- Tap target sizing
- Mobile-first audit
- Lang attribute check
- Contrast analysis
- Form labels
- ARIA landmarks
Backlink and referring domain analysis — in development
This is on the roadmap, not in the product. Dr Urls does not currently collect backlink or referring-domain data, and we would rather tell you that here than have you find out after paying. Everything else on this page is live today.
Referring Domains
Will track every domain linking to your site with quality scores, anchor text, and follow/nofollow ratios.
Backlink Monitor
Will detect new, lost, and broken backlinks, and track redirect chains and link decay.
Toxic Link Detection
Planned heuristic toxicity scoring to identify suspicious link patterns and potential spam.
Competitor Link Gap
Will surface domains linking to competitors but not to you, prioritised by relevance and difficulty.
Anchor Text Analysis
Will analyse anchor text distribution for naturalness and detect over-optimised patterns.
Link Opportunities
Planned AI suggestions for broken link reclamation, unlinked mentions, and competitor gaps.
Scores you can trust and explain
Every score is broken down by category with clear weights. No black boxes. No vanity metrics. Just actionable numbers.
- Website Health Score: 10 weighted categories, 0-100
- Issue Priority Score: severity x impact x ease of fix
- Domain Quality Score: diversity, freshness, naturalness
- Trend tracking with week-over-week changes
Why Dr Urls
We focus on what matters: honest data, transparent scoring, and a tool you can trust.
Open & Transparent
Every score weight is documented. No black-box algorithms.
Free plan, no card
1 site, 5 credits a month, every check. Upgrade only when you outgrow it.
Privacy First
Your data stays yours. EU-hosted, GDPR compliant.
Built for Speed
Full site audits in minutes, not hours. Real-time progress tracking.
And what each one cannot do
Every capability below is shipped and running. Each also states its limits, because you will meet them eventually and it is cheaper for both of us if you meet them here.
Whole-site crawl
Crawls every reachable page from the sitemap and internal links, not just the URL you typed.
Limits: Cannot see pages behind a login, pages reachable only by form POST, or content a client-side router renders without a distinct URL. The page budget is the plan's pagesPerScan, so a larger site is sampled by URL-pattern diversity rather than crawled exhaustively.
Ranked issues with the exact fix
Every finding carries a severity and the specific change that clears it, ranked by impact rather than listed alphabetically.
Limits: Severity is a fixed property of the issue code, not a judgement about your particular site — a missing H1 scores the same on a landing page and a legal notice. Codes in CODES_WITHOUT_EMITTER are defined but nothing raises them.
SEO health score
One number per scan, density-based so a big site is not punished simply for having more pages.
Limits: Not comparable to any other tool's score, and not comparable to v1 scores on historical scans — those rows are rendered with the v1 formula on purpose. It measures what we check, so it cannot reflect anything outside the issue registry.
Instant check, no account
One URL, a real result, no sign-up — the fastest way to see whether this is useful.
Limits: One page, not the site, and rate-limited per IP. Results are not saved to an account unless you create one, so there is nothing to compare a later run against.
Screenshots and screencasts
Capture what you are looking at, annotate it, and send it to the project as a tracked item.
Limits: Media lives in a private bucket and is served only through the authenticated proxy, so a capture cannot be hot-linked or shared as a public URL. Recording happens in the Chrome extension — nothing captures server-side.
AI review of a screenshot
Ask a model what is wrong with a screen, against a preset or your own question.
Limits: Judges only what is visible in the image — it cannot read your code, your analytics or anything below the fold that was not captured. Server-side review needs Vertex, which is unavailable in local dev by design.
Recorded test flows
Record a journey once and replay it to prove a fix worked, in a real browser or headless.
Limits: A headless replay cannot hold a session, upload real bytes or drag with real pointer physics — those steps are recorded as skipped and force a PARTIAL result rather than a pass. A real-browser run needs a person to accept the prompt.
Tasks with evidence attached
One unit of work that carries what is wrong (captures, issues) and how to know it is right (a flow).
Limits: Evidence ids are client-supplied opaque strings pointing at one of three tables, so a resolver omits what no longer exists rather than failing — a task can quietly lose evidence that was deleted elsewhere.
Roles on a website, not on an account
Two teams who provably run the same website share one record of it, with admin / developer / tester roles on the site itself.
Limits: The only proof of ownership is Google Search Console listing you as an owner or full user of the property — DNS and HTML-file verification are not implemented, so a site whose owners have never connected Search Console starts with an empty roster and nobody who can grant a role on it. Roster reads span both teams' workspaces; writes need a role, and a workspace nobody on the roster owns (a competitor auditing the same domain) is never reachable in either direction.
Agent-ready Markdown briefs
Copy any audit as Markdown a coding agent can act on without further explanation.
Limits: It describes findings, not your codebase — it cannot know which file produces which page. Nothing is sent to any agent from here; a human copies it or the VS Code companion writes it locally.
Credits
One unit of consumption for everything metered, with a per-tier price that falls as the plan rises.
Limits: The check-then-charge order means a customer spending their last credits in two tabs at once can overshoot by an action or two. That is deliberate: over-delivering a credit beats charging for work that failed.
Plans
Four tiers that change three enforced numbers and two human commitments, and nothing else.
Limits: A plan grants no capability that credits do not — there is no feature behind a plan boolean, by design. Enterprise's allowance is unlimited and therefore unbounded in cost; nothing caps it.
Two-sided referrals
Both sides get credits, commission runs two tiers deep, and payouts are idempotent by construction.
Limits: Bonuses are paid in credits, never cash, and there is no tier 3 — a second row rather than a recursive walk. Nothing writes a UsageEvent when granting, because that table is consumption only.
Follow-up sequence
Three notes over two weeks to someone who ran a check, each about their own result.
Limits: Skips any lead with no score — there is nothing specific to say. Stops on unsubscribe, on signup, or after three messages; it is not a mailing list and there is no way to re-enter it.
One suppression list
Every send passes one policy layer: do-not-contact honoured, one-click unsubscribe on anything marketing.
Limits: Suppression is keyed on the address, so the same person using a second address is a second recipient. Bounces and complaints are not yet fed back into the list automatically — only explicit unsubscribes are.
REST API
The same endpoints the dashboard uses, on every plan, priced per call in credits.
Limits: Keys are gated to /api/v1/** non-admin paths by middleware — a key can never reach an admin route or a page route. There is no plan gate, so abuse is bounded by the allowance and the rate limit rather than by the door.
MCP server
An agent can audit a site and read results as tools, with each tool stating its price.
Limits: Every tool scopes data by orgId, so it needs a key belonging to an organisation — an agent with only a wallet has no org and cannot be served.
Machine-readable surface
llms.txt, pricing.md and a well-known descriptor, all generated from the same source.
Limits: It advertises only paths that answer — an advertised 404 is worse than silence, so two tests fail the build if a listed path has no route.
Ready to see what's under the hood?
Start your free audit today. No credit card required.
Start freeNo credit card required