Feature

Site health that checks itself

14 services check every project on a schedule, and every check ends in a 0–100 score, an A–F grade and a list of concrete findings. An alert arrives only when the state changes.

No payment card · Unlimited reporters · Interface in 6 languages

Why it matters

If the client notices first, that is already bad news

A certificate that expired. A page that got twice as slow. A cookie set before consent. None of them send an email.

How it goes today

  • The site goes down at night and the client notices in the morning.
  • Security headers and TLS config stay the way they were on launch day.
  • Every audit means someone walking through the same checklist by hand.
  • A separate tool, a separate subscription and a separate login for every question.

With Bugzio

  • Checks run on a schedule, without a reminder.
  • Every result is a number, a grade and a list of concrete findings.
  • An alert fires only when the state changes — and again when it is resolved.
  • All projects and all services in one panel, in six languages.

The result: the client report is ready before the client asks for it.

What you get

What monitoring gives you

Every service follows the same shape: a score, a grade and findings marked pass, warning or fail.

Uptime and response time

HTTP checks at the frequency your plan allows — as often as every 30 seconds. Each measurement stores the status code and the response time, so a slowdown is visible before an outage.

Speed, measured by Lighthouse

Google PageSpeed Insights runs at a plan-defined cadence. The history shows whether the last release made the page faster or slower.

Security, TLS and malware

HTTP security headers, cookie flags, CORS, exposed files and panels, certificate configuration, plus a content scan for obfuscated code and unexpected redirects.

Visibility in search

Titles, meta descriptions, the canonical URL, indexability, social tags, image alt coverage, robots.txt and sitemap.xml.

Accessibility and compliance

A WCAG 2.2 AA audit with axe-core across several viewports, and a GDPR scan that records cookies and trackers set before consent is given.

Alerts without the noise

An alert goes out only when a service moves from a good state to a bad one, and once more when the problem is resolved — not on every check. Delivery is set up with us: email, and SMS on request.

Checks that have already run

More than 48,000 automated checks have run so far, 44,414 of them uptime checks. It is the same system that will run on your projects.

One view across every project

A grade, a score and findings per service. A finding points at the specific place, not at a generic recommendation.

app.bugzio.com/lab/security
Bugzio security service results with a grade and findings

How it works

How to turn it on

The services live in the project settings. Switch on what you need; the rest happens in the background.

Add a project

An address and a domain. The check targets for each service are created from them.

Enable the services

Per project. The plan decides how often the checks run and how long the history is kept.

Get the alerts

By email, with SMS on request; we set the recipient up with you. The full history stays in the panel, so a client report can be produced at any moment.

The full list

The 14 services

Each of them can be switched on separately, per project.

  • Uptime. HTTP checks with status code and response time; the frequency is set by the plan.
  • PageSpeed. Google PageSpeed Insights (Lighthouse) measurements and their history.
  • Security. HTTP security headers, cookie flags, CORS, exposed files, security.txt and TLS configuration.
  • SEO audit. Titles, meta tags, canonical URL, indexability, alt text, robots.txt and sitemap.xml.
  • WCAG accessibility. A WCAG 2.2 AA audit with axe-core; violations are weighted by how severe their impact is.
  • GDPR scan. Cookies and third-party trackers set before consent, plus detection of the consent tool itself.
  • DNS monitoring. A, AAAA, MX and NS records compared against the previous snapshot, and the resolved IPs checked against blacklists.
  • Email authentication. SPF, DMARC including its policy, DKIM (probing the common selectors) and MX records.
  • CDN audit. The live CDN zone settings compared against the profile you defined.
  • WordPress scan. Updates, vulnerabilities, configuration, database and content; a critical finding caps the grade at D.
  • Image optimisation. Local WebP conversion and compression, without sending images to a third-party service.
  • Image audit. Every image on a page is actually re-encoded (WebP/AVIF and the right dimensions) to show how many bytes are waste — with the full file list.
  • Malware scan. The page is opened in a real browser and checked for obfuscated code, cryptominers, skimmers and redirects.
  • Blacklists. Domain and IP against DNSBLs and locally cached feeds; every listing comes with its delisting details.
14monitoring and audit services
A–Fa grade for every check
48,000+automated checks already run
44,414of them uptime checks

Let the site tell you when something changes

Turn monitoring on for one project and see what the 14 services find on your site today.

No payment card · Unlimited reporters · Interface in 6 languages