Canopy: Grade any website's health in 4 seconds

jjraxx1 pts0 comments

Canopy: grade your site's health in seconds

Skip to content

Grade any website in four seconds.

Twelve analyzers: security headers, CSP, cookies, privacy & trackers,<br>AI readiness, email, DNS, SEO, performance, accessibility, links & PWA. Each returns a letter<br>and the exact fix.

Free, no account<br>Unlimited scans

CI gate included<br>Grades its own site

Scan

How much to scan

Everything one combined grade

Headers only faster

Try: this site ·<br>github.com ·<br>example.com

Live examples — real grades, updated hourly

github.com

full report →

wikipedia.org

full report →

stripe.com

full report →

nytimes.com

full report →

Scan & monitor<br>7 tools<br>Whole-site scan<br>11 layers at once, one combined grade.

Multi-page sweep<br>Your sitemap's pages checked together: drift shows up per page.

Dashboard<br>All your domains as a live wall of grade badges on one URL.

Uptime<br>Pinged every 15 minutes, public status pages, 7 days of history.

Trends<br>Every monitored grade over time, in one view.

Weekly digest<br>What changed across your sites this week, regressions first.

Compare<br>Two URLs side by side on any layer, drift highlighted.

Twelve graded layers

01Security headers<br>HSTS, framing, sniffing, CORS, mixed content: 15 checks.

02CSP deep-dive<br>Reads your policy the way an attacker would.

03Cookie security<br>Every Set-Cookie, inspected like a browser does.

04Privacy & trackers<br>Which analytics, ad pixels & recorders watch your visitors, and do you ask consent?

05Email security<br>SPF, DMARC, DKIM: can strangers send mail as you?

06DNS posture<br>DNSSEC, CAA, redundancy, IPv6.

07SEO & meta<br>Titles, descriptions, canonicals, OG, sitemap.

08Performance<br>TTFB, blocking scripts, layout shift, third-party fan-out.

09Accessibility<br>Alt text, labels, zoom, heading order: WCAG smoke test.

10Link health<br>Dead links, stale redirects, insecure targets, probed live.

11AI readiness<br>Does your site say whether AI crawlers may read it?

12PWA & installability<br>Manifest, icons, display mode: can it be installed as an app?

Fix & automate<br>17 tools<br>Fix pack<br>A config for your server containing only the fixes you need.

Reference configs<br>The full A-grade setup for six stacks, copy-ready.

CI gate<br>curl with fail_under=B blocks deploys that regress.

Badges & snapshots<br>Live grade badges for READMEs; 90-day frozen report links.

Redirect tracer<br>Follow a URL hop by hop: loops, downgrades, wasted hops.

Exposed files<br>Is your .git, .env, a DB dump or phpinfo() reachable? Content-verified, no false alarms.

security.txt<br>Check or generate your RFC 9116 vulnerability-disclosure policy, expiry and all.

robots.txt<br>Valid, or secretly an HTML page, or one stray Disallow: / from deindexing you? Read as a document.

Sitemap audit<br>Is your sitemap.xml valid XML, within Google's 50k-URL cap, and full of absolute HTTPS URLs, or secretly an HTML 404?

Social preview<br>See how a link unfurls on X, Facebook, Slack, before you post.

SERP preview<br>See your title and description as a Google result — with the real pixel width that decides whether your title survives or gets cut with an ellipsis.

Schema generator<br>Generate paste-ready JSON-LD for review stars, FAQ, breadcrumbs, or paste your own and check it wins the rich result, against Google's rules.

CSP builder<br>Build a hardened Content-Security-Policy from what your site loads (Analytics, Fonts, Stripe, YouTube), starting from default-src 'self'. The author-side mirror of the CSP layer.

Email records<br>Generate correct SPF & DMARC records from who sends your mail (Google, Microsoft 365, SendGrid, SES), or lock down a domain that sends none. The author-side mirror of the email layer.

robots.txt builder<br>Generate a valid robots.txt: keep admin & cart paths private, declare your sitemap, and opt out of AI training while staying citable in ChatGPT & Perplexity answers. The author-side mirror of the robots.txt and AI layers.

SRI hashes<br>Generate Subresource Integrity hashes for the CDN scripts and styles you embed, so the browser refuses a file a hijacked CDN has swapped — plus the CORS check that stops SRI silently breaking the load.

Pro (waitlist)<br>Alerts on regressions, private slots, higher limits.

What the header scan checks<br>15 checks

HTTPS enforcement (HTTP → HTTPS redirect) · Strict-Transport-Security ·<br>Content-Security-Policy · X-Content-Type-Options ·<br>clickjacking protection (X-Frame-Options / frame-ancestors) · Referrer-Policy ·<br>Permissions-Policy · Cross-Origin-Opener-Policy · cookie security<br>(Secure / HttpOnly / SameSite) · CORS (Access-Control-Allow-Origin<br>reflection & credentials) · mixed content (http:// scripts, styles,<br>frames & images on HTTPS pages) · Subresource Integrity on third-party<br>scripts/styles · cache-control sanity · security.txt (RFC 9116) ·<br>information disclosure (Server / X-Powered-By).<br>Each rolls up to a letter grade with the exact fix to apply.

grade security content policy site full

Related Articles