SecAudit · live · non-invasive
Know your exposure.
Before someone else does.
A live audit of your website, IP, GitHub repository or page: header hardening, CSP, TLS, exposed files, open ports, leaked secrets, an AI senior-reviewer pass over your code, and a full SEO / AI-visibility / performance report for your pages, plus an anti AI-slop review that grades how generated your design and copy read. Every audit runs live against your target — nothing cached, nothing canned. An AI analyst reads the findings with you and tells you what to fix first, every finding is then re-checked by a second-pass verification layer, and the report ends with a copy-paste fix prompt your dev agent can execute. Each scan also hands you a compare token: bring it to your next audit and the report opens with exactly what you fixed, what is still open and what is new.
Find the holes attackers probe first: missing protection headers, TLS gaps, exposed files, ways to spoof your email. About a minute.
Every report ends with one. Paste it here to see fixed / still open / new.
Carries X scans. Redeemed one per audit, every kind, no 24-hour cap.
Your report ends with a fix prompt. Give it hands.
Every SecAudit brief above is written for a coding agent: plan, patch, close. GLM 5.3 Flash is the coding-tuned brain built for exactly that loop: it reads the fix brief, edits your repo and runs the checks. The launch bundle takes 10% off all Z.AI GLM coding plans.
Coverage
11 check families. One verdict.
The same checks a pentester runs on day one (minus the exploitation), plus a full GEO/SEO/performance grade for your pages, and an unslop pass that finds the defaults you never chose. Each family maps to concrete findings with severity and remediation, not a vague score.
01 · HTTP headers
HSTS, Server/version leaks, X-Content-Type-Options, clickjacking, Referrer-Policy, cookie flags, open-redirect probes.
02 · CSP lint
ZAP-equivalent rules: missing default-src fallback, wildcards, unsafe-inline / unsafe-eval, frame gaps.
03 · TLS config
Certificate expiry, TLS 1.0/1.1 still enabled, self-signed certs: the stuff browsers quietly punish.
04 · Sensitive files
.git/HEAD, .env, .next/BUILD_ID, wp-login, /server-status, /metrics, with 404-baseline aware probing.
05 · TCP ports
Fixed port list for websites, optional top-1000 sweep for IPs. Anything open beyond 80/443 gets flagged.
06 · Repo secrets
GitHub audits: AWS/Slack/OpenAI-style tokens, private key blocks, tracked .env files, old dependency floors.
07 · AI code review
Repo audits: a senior-reviewer AI reads key source files with a strict review checklist: logic, error handling, auth boundaries, injection risks. It leaves blocking / important / nit notes with file references, concrete fixes and a clear verdict.
08 · SEO · GEO · Performance
Full page report: GEO score for AI-answer visibility (ChatGPT, Claude, Perplexity, Gemini), classic SEO grading, live-measured TTFB / load / weight, robots + sitemap, with code-level fixes.
09 · Email spoofing protection
Website audits: your domain’s public SPF, DMARC, DKIM, MTA-STS and security.txt records — whether phishers can send email that looks like it comes from you, and how to shut it down.
10 · Letter grades & share links
Website audits open with A+ to F grades per layer (headers, TLS, exposure, ports, email) — the ten-second read. One click turns any report into a read-only share link that expires in 72 hours.
11 · Anti AI-Slop review
A blunt design + content audit for AI-generated tells: purple-gradient defaults, identical card grids, icon tiles above every heading, stock typefaces, contrast fails, buzzword walls, em-dash overuse and uniform sentence rhythm. Ships a 0-100 slop score with an A-F grade, a what-to-keep list, an unslop direction and a copy-paste fix prompt.
Questions, answered.
Is the scan safe for my site?+
Yes. The scanner is non-invasive by design: normal HTTP(S) requests and plain TCP connects only. No exploitation, no payloads, no DoS. A web audit sends roughly 15-25 requests total, and redirects to other hosts are observed but never followed.
What do you do with my GitHub token?+
If you paste one, it lives in server memory for the duration of a single shallow clone, is never logged, never stored, and is scrubbed from every byte we send back. When the audit ends it is gone. Open repos need no token at all.
What can I audit?+
Websites (any public hostname or URL), public IPv4/IPv6 addresses (with an optional top-1000 port sweep), GitHub repositories (public ones directly, private ones with a read token), full AI code reviews of those repositories, any page for a full SEO / GEO / performance report. Sites can also be graded for AI-generated design and copy tells (the Anti AI-Slop review). You must own the target or have written permission to test it.
What does the AI code review check?+
The Code review tab runs the full security scan AND a senior-reviewer pass over sampled source files: logic and edge cases, error handling, injection and XSS escape hatches, authorization gaps, performance traps like N+1 queries, and reliability red flags. Notes are labeled blocking / important / nit / suggestion with the file they refer to, plus an overall verdict (approve / comment / changes requested). The same discipline a strict human reviewer applies.
What leaves my repository during a code review?+
Up to eight source files (a bounded sample, code files only) are sent to the AI analyst so it can reason about your code. Before anything leaves the server, secret-shaped strings (tokens, keys, private-key blocks) are redacted, and files the scanner flagged for secrets are excluded from sampling entirely. Nothing is stored after the report is delivered.
What is GEO and how is the SEO report built?+
GEO (Generative Engine Optimization) measures how easily AI answer engines (ChatGPT, Claude, Perplexity, Gemini) can read, trust and cite your pages. The SEO · AI visibility scanner grades twelve signals (structured data, AI readability, citation readiness, titles, headings, links), adds live-measured performance (TTFB, fetch time, page weight, robots.txt, sitemap), and every finding ships with a concrete, code-level fix.
How do I read the results?+
Website audits open with letter grades (overall, headers, TLS, exposure, ports, email) — the ten-second read. Every finding has a severity, a plain-language detail and a remediation, plus a verification badge from the second pass: ✓ verified, ~ heuristic (context decides) or ? manual check. Open a finding to see the verifier’s one-line reasoning. The AI analyst on top gives you the two-minute read: overall posture and the three actions that matter most, in priority order.
What does Share report do?+
It creates a read-only link to this exact report. Anyone with the link sees the same findings, grades and fix prompt — no form, no scanning. The snapshot lives for 72 hours, then deletes itself automatically; nothing else is stored, and a report is only ever saved when you press Share. Great for handing your developer or your boss the full picture without screenshots.
Are the findings verified?+
Yes. Before a report ships, every finding goes through a second pass. High-risk website checks (headers, TLS-adjacent probes) are re-confirmed with an independent second request against your live target, so one hiccup response or CDN edge variance cannot pose as a finding. Every finding (including SEO and code-scan results) is then judged by a skeptical AI verifier and labeled ✓ verified, ~ heuristic or ? manual check, with a one-line reason. If the verifier is unavailable, findings are honestly marked unverified, never silently passed. Heuristic does not mean wrong, it means context decides.
How do I get the issues actually fixed?+
Every report ends with a “Fix it with your dev agent” block: a ready-to-paste prompt containing the full issue list in priority order, concrete fixes, working rules (rotate leaked credentials, close root causes, keep changes behavior-compatible) and acceptance criteria. Copy it into your coding agent (Cursor, Claude Code, Codex, Copilot), let it plan and patch, then re-run the same audit to confirm the findings are gone.
How does progress tracking between scans work?+
Every report ends with a compare token, a short string that encodes which checks failed and how severe they were, hashed and checksummed. Save it; on your next scan of the same target, paste it into the form (it auto-fills from your browser) and the report opens with a comparison: what got fixed, what is still open, what is new, and whether your score moved. The token never contains your URLs, code or findings in plain text, and nothing is stored on the server; if you lose it, the history is gone. It compares the same checks between two runs: a progress meter, not a guarantee.
Need more than 3 scans?+
The free tier is 3 audits per 24 hours; that keeps each scan deep, fast and unmolested for everyone. If you have a usage token, paste it in the form: each token carries a fixed number of paid scans, redeemed one per audit with no 24-hour cap. The moment you paste a token, the form shows how many scans are left on it and which scan types it covers. Some tokens are limited to specific kinds (a website-only token covers website audits but not the other kinds). Teams, CI pipelines and client work can order additional scan tokens: email sales@xshredo.com with your expected volume and we will size it to your workflow.
What does the AI-Slop reviewer check?+
It reads your site the way a skeptical designer and editor would. Deterministic probes measure the design tells (purple-gradient defaults, gradient text, identical card grids, icon tiles above every heading, one bubbly radius on everything, glass surfaces, stock typefaces, WCAG contrast failures, touch targets) and the content tells (AI-tell vocabulary per 1000 words, em-dash density, not-just-X-but-Y cadence, generic-adjective triads, transition clusters, uniform sentence rhythm, fake precision numbers, placeholder names). Then an AI editor adds the judgment finds a script cannot see (cookie-cutter section rhythm, testimonials nobody said, stock heroes) and ships a what-to-keep list plus an unslop direction. The point is not to shame the template: it is to find the defaults that were never chosen.
What does the slop score mean?+
It is a 0-100 grade where 100 means every detail looks decided and 45-and-below means the page reads as assembled from defaults. High-severity tells (purple-gradient scheme, buzzword wall, system font as brand voice) cost the most; every rule is capped so one runaway pattern cannot drown the report. Handcrafted sites with deliberate choices land A/B, competent template work lands C, and pages with the full AI-default stack land D/F. The score is computed per scan and never stored on our side; the compare token tracks what you fixed between runs.
Can the scanners touch anything else on your servers?+
No. Every scanner process runs as a dedicated unprivileged account with no shell access, no read access to application files, configuration or data, and a firewall rule set that refuses all traffic to private networks, the host itself and cloud-metadata addresses. Only public internet destinations are reachable from the sandbox. A scanner failure stays inside the sandbox.
What does the operator store about my scans?+
As little as the product can run on. Your report itself is assembled in server memory, delivered to your browser and then gone: no findings, no report content, no tokens, no contact data — the one exception is a snapshot you deliberately create with Share report, which expires and deletes itself after 72 hours. What the operator keeps is a minimal ops record per scan (time, scan type, target host, outcome, severity counts, duration, how it was paid) for capacity planning and abuse prevention, an anonymous remaining-scans counter for redeemed usage tokens, and feedback you actively submit. Full report copies are off by default; when enabled for support purposes they are only visible to the operator. The compare token lives only where you save it, and the comparison is recomputed from it on every scan.
The honest part
Two truths about automated scanning.
We would rather tell you this upfront than hide it in a footer.
01 · Fair use
Scans cost real compute. Free means fair.
A SecAudit run is never a cached page. Every audit wakes the scanner, touches your target live, then feeds each finding to an AI analyst that actually reads them: real tokens, real compute, real bandwidth, every single run. That is why the free tier is 3 audits per 24 hours; it keeps every scan deep and fast, instead of a free-for-all that ruins it for everyone.
Need more volume? Teams, CI pipelines and agencies can order additional scan tokens, sized to your workflow, priced honestly.
Order scan tokens: sales@xshredo.com02 · No silver bullets
No single tool catches everything. Ours doesn't pretend to.
SecAudit is a point-in-time, non-invasive look at what your target exposes to the public internet. roughly the first pass an attacker makes. It cannot see behind logins, inside your business logic, or into a zero-day nobody knows about yet. A clean report is not a security certificate. A finding is not a breach.
Every professional scanner carries this fine print; we simply say it out loud. Results are advisory and provided as-is, without warranty of any kind; always verify findings on systems you own. Then keep the practice that actually protects you: layered defenses, fast patching, least privilege, constant monitoring. Use SecAudit as the flashlight. You still have to build the fortress.
Audited the box. Now own one that stays clean.
Every xShredo bare metal and KVM VPS ships hardened: minimal surface, DDoS protection, full root. Deploy in Tampa FL in minutes.