FREE WEB APPS
Find out what is happening on your website.
Search appearance, connection settings and writing. Pick an app for the task at hand.
Choose what to inspect
About data sent to the server
SERVER PROCESSING — this site processes data on the serverApps here run part of their work on the server (Cloudflare). Each app states what is sent, what is stored, and when it is deleted. If you want processing that never leaves your device, use our fully client-side tools instead.
-
GEO Checker
Enter a URL and get a six-axis, 100-point diagnosis of how citable your site is for AI search.
Only the URL you enter is sent. We never re-serve the fetched page and store nothing (it is gone when the request ends).
-
Meta Tag & SEO Basics Check
Enter a URL to grade its title, meta description, canonical, robots, h1, OGP, lang and viewport. Character counts and robots.txt crawlability are checked too.
Only the URL you enter is sent. We never re-serve the fetched page and store nothing (it is gone when the request ends).
-
Security Header Grader
Enter a URL to grade CSP, HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy out of 100, with an A–F verdict, plain-language explanations and recommended values.
Only the URL you enter is sent. We return the grade and the graded header values only — never the page body — and store nothing (it is gone when the request ends).
-
SSL/TLS Certificate Checker
Enter a hostname and we run a real TLS handshake to read the certificate being served: expiry, days remaining, issuer, SAN and the intermediate chain, with a warning under 30 days.
Only the hostname you enter is sent (as TLS SNI). We return the fields read from the certificate and store nothing (it is gone when the request ends).
-
Redirect Chain Tracer
Enter a URL and we follow 301, 302, 307, 308 and meta refresh redirects one hop at a time, listing the status, URL and timing of each step, the final destination, and an SEO warning at three or more hops.
Only the URL you enter is sent. We return the status, URL and timing of each hop — never the fetched page — and store nothing (it is gone when the request ends).
-
Bulk HTTP Status Check
Paste up to 20 URLs and get the HTTP status, response time and final URL after redirects for each one — for post-relaunch smoke checks and link-list clean-ups. One-off checks only; no scheduled monitoring.
Only the list of URLs you paste is sent. We return the status, response time and final URL only — the page body is never read — and store nothing (it is gone when the request ends).
-
Broken Link & Image Alt Checker
Enter a URL to extract its links (a href), fetch up to 40 of them and surface the broken ones, plus a list of images with missing or unhelpful alt text. Only the page you enter is examined — never a whole-site crawl.
Only the URL you enter is sent. We return the extracted link URLs with their status and the alt verdicts — never the fetched HTML — and store nothing (it is gone when the request ends).
-
OGP Check (by URL)
Enter a URL to inspect its og: / twitter: tags and preview the X and Facebook cards. The og:image is fetched and measured, not just read from the markup.
Only the URL you enter is sent. We never re-serve the fetched HTML or image and store nothing (it is gone when the request ends).
-
Heading Structure (h1–h6) Extractor
Enter a URL to see every h1–h6 as an indented outline in document order. Multiple h1s, skipped levels and empty headings are flagged, and the outline copies out as Markdown.
Only the URL you enter is sent. We never re-serve the fetched page and store nothing (it is gone when the request ends).
-
Structured Data (JSON-LD) Extractor & Validator
Enter a URL to extract every JSON-LD block and pretty-print it by @type. Syntax errors are pinpointed with line and column, and required/recommended properties are listed for Article, FAQPage, BreadcrumbList, LocalBusiness and Organization.
Only the URL you enter is sent. We return the extracted JSON-LD re-assembled for display plus our findings — never the fetched HTML — and store nothing (it is gone when the request ends).
-
AI Crawler Access Checker
Enter a URL to fetch its robots.txt and see, bot by bot, whether GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot, Bytespider and others may crawl it — including the Disallow that matched, llms.txt presence and X-Robots-Tag.
Only the URL you enter is sent. We return verdicts and file presence only — never the fetched robots.txt or HTML — and store nothing (it is gone when the request ends).
-
robots.txt Tester
Enter a URL and a user-agent to fetch the site's robots.txt and rule on whether that URL may be crawled, following Google's matching rules (longest match wins, ties go to Allow). The winning rule and the rules it beat are shown with line numbers, plus syntax warnings.
Only the URL and user-agent you enter are sent. We fetch just that site's /robots.txt, never re-serve it, and store nothing (it is gone when the request ends).
-
sitemap.xml Validator
Enter a sitemap URL to fetch it, validate the XML, and see the URL count, the spread of lastmod dates and what a sitemap index points at (one level deep). Raw `&` and unclosed tags are reported with line numbers; robots.txt discovery and gzipped sitemaps are supported.
Only the URL you enter is sent. We never re-serve the fetched XML — only counts, the lastmod spread, warnings and the first 200 extracted URLs — and store nothing (it is gone when the request ends).
-
hreflang Return-Link Checker
Enter a URL to extract its hreflang annotations (link rel=alternate and the HTTP Link header) and verify the return links by actually fetching each declared page. Self-reference, x-default and invalid language/region codes such as en-UK or jp are checked too.
Only the URL you enter is sent. We also fetch the declared pages, but never re-serve them — only the hreflang values, URLs and verdicts — and store nothing (it is gone when the request ends).
-
Mixed Content Checker
Enter a URL to list every http:// reference left inside an https page (img, script, link, iframe, video, source and CSS url()), with its line number, the offending tag and how to fix it. References browsers block are separated from the ones they auto-upgrade.
Only the URL you enter is sent. We fetch that single page and never request the http:// URLs found inside it. The page itself is never re-served and nothing is stored (it is gone when the request ends).
-
Page Image Audit
Enter a URL to audit every img / picture on the page: format (WebP / AVIF adoption), loading=lazy, width/height attributes and alt text. For the first 30 images the real file size and served format are measured with a HEAD request.
Only the URL you enter is sent. Neither the page nor the images are re-served and nothing is stored (it is gone when the request ends).
-
Tech Stack Detector
Enter a URL to infer the CMS (WordPress, Shopify, Wix, STUDIO and more), framework, CDN, analytics tags (GA4/GTM) and web fonts from HTML and header signatures — always with the evidence behind each guess.
Only the URL you enter is sent. We return just the matched strings — never the page or a header dump — and store nothing (it is gone when the request ends).
-
WordPress Quick Audit
Enter a URL to see whether the site runs WordPress, which theme it uses, the version it announces, and whether REST API username enumeration, xmlrpc.php, author archives, the default login URL, readme.html or a debug log are exposed. Read-only GETs, never enumeration.
Only the URL you enter is sent; the seven default paths are fetched only when a WordPress fingerprint is found. Usernames are never returned (count only), neither is the page itself, and nothing is stored.
-
RSS/Atom Feed Validator
Enter a feed URL or a site URL: we discover the feed, fetch it, and validate its XML syntax, required elements, item list, character encoding and date formats (RFC 822 for RSS, RFC 3339 for Atom). Feeds using the itunes namespace also get the Apple Podcasts required-element check.
Only the URL you enter is sent. The feed itself is never re-served (you get findings and truncated excerpts) and nothing is stored.
-
Favicon Checker
Enter a URL to extract every icon declaration (favicon.ico, link rel=icon, apple-touch-icon and Web App Manifest icons), fetch each one and list its real format, dimensions (every size inside an ICO) and weight — with light and dark previews.
Only the URL you enter is sent. We never re-serve the fetched HTML, manifest or images and store nothing (it is gone when the request ends).
-
DNS Record Checker
Enter a domain and we query Cloudflare DoH (1.1.1.1) for its A, AAAA, CNAME, MX, TXT, NS, SOA and CAA records, then check where www points, whether SPF is published exactly once, and whether CAA exists — no dig required.
Only the domain name you enter is sent (as ten queries to Cloudflare's public DNS). Nothing is stored (it is gone when the request ends).
-
DNS Propagation Check
Enter a domain and a record type; we ask five public resolvers (Cloudflare, Google, OpenDNS and more) at once and line up their answers. TTL and SOA serial separate a propagation delay from a misconfiguration.
Only the domain name and record type you enter are sent (as ten queries to five public resolvers). Nothing is stored (it is gone when the request ends).
-
Email DNS Checker
Enter a domain and we look up MX, SPF, DKIM and DMARC. We follow every include: to count the SPF DNS lookups against the limit of ten, explain the DMARC policy, and check it all against Google's sender guidelines (2024).
Only the domain name and DKIM selector you enter are sent (up to 40 public DNS queries). No message content is involved and nothing is stored (it is gone when the request ends).
-
Domain Info & Expiry Checker
Enter a domain and we query RDAP (the successor to WHOIS) for the registrar, creation date, expiry date, EPP statuses such as clientHold, and name servers. Days until expiry and renewal warnings come first. gTLD servers are resolved via the IANA bootstrap; TLDs without RDAP (including .jp) are reported as such.
Only the domain name you enter is sent (at most two HTTPS GETs: the IANA bootstrap and the registry's RDAP server). We never read registrant or admin contacts, and nothing is stored (it is gone when the request ends).
-
Bulk Domain Availability Check
Enter one candidate name and we check .com, .net, .org, .jp, .co.jp, .dev, .io, .ai, .app and .co at once using RDAP and public DNS. Verdicts are three-way — registered, possibly free, inconclusive — and we never claim a name is definitely available (no affiliate links either).
Only the name taken from your input is sent (at most 44 lookups to the IANA bootstrap, registry RDAP servers and public DNS). We never read registrant contacts, and nothing is stored (it is gone when the request ends).
-
IP & Request Info
Shows the public IP, estimated country/city, network (ASN), HTTP/TLS details, User-Agent and main request headers of your current request. Handy for VPN checks and support tickets. Send Accept: text/plain and you get just the IP.
Only the request that opened the page (your IP and headers) reaches the server. It is displayed and never recorded — not even in access logs.
-
Brand Fetch
Enter a domain to extract the site's logo, favicons, main colours and company description. Colours are ranked by CSS frequency with contrast ratios on white and black — handy for placeholder branding in proposals and mock-ups.
Only the domain you enter is sent. We never re-serve the fetched HTML, CSS or images (images come back as URL and size only) and store nothing (it is gone when the request ends).
-
Japanese Business Tone Check
Paste a Japanese business email or proposal to flag phrases that may read as rude, vague, double keigo or too pushy, with drop-in rewrites and cultural pitfalls for English translation (AI-generated advice).
Only the text you enter is sent (checked with Cloudflare Workers AI). Neither the text nor the result is stored (only the date and the total usage count are).
-
LP Copy Persona Check
Paste landing page copy and pick an industry (professional services, e-commerce or B2B SaaS) to get estimated scores and comments on clarity, trust, formality and purchase intent from three simulated Japanese buyer personas (AI-generated advice, not real customer feedback).
Only the copy and industry you enter are sent (evaluated with Cloudflare Workers AI). Neither the copy nor the result is stored (only the date and the total usage count are).
-
Japanese Readability Checker
Enter a URL to check the Japanese typography of its body text: one-character orphan lines, punctuation at line start, characters per line against the 35–40 guideline and missing Japanese font fallbacks, estimated for desktop and mobile.
Only the URL you enter is sent (we fetch the page and its CSS). We never re-serve the fetched page and store nothing (it is gone when the request ends).