Skip to content

Changelog

What changed, newest first. Checks are added a few at a time; each one gets a guide.

  1. Hosting speed check: your host against its peers

    • Hosting speed check: who serves your site (host, network, CDN) and how fast its server sends the first byte, next to the median of other sites we checked on the same host.
    • The host comparison is anonymous: every night we compute percentiles from the latest check of each site, store no site names, and show a number only once a host has 50 different sites. Reports on WordPress and other sites now include it in the speed section.
  2. Tech stack checker with known vulnerabilities

    • Tech stack & vulnerabilities: the CMS, frameworks, libraries, analytics, consent platform, CDN and server behind any page, with versions and the evidence for each.
    • Every JavaScript library with a readable version (jQuery, Bootstrap, Lodash, Moment.js, AngularJS and more) is matched against OSV.dev, the open vulnerability database. Each advisory shows its CVE, severity and the version that fixes it, and every report now flags vulnerable libraries.
  3. Compare your speed with competitors, and PageSpeed for 50 URLs at once

    • Competitor speed comparison: your site and up to four others side by side, on the PageSpeed score, real-visitor Core Web Vitals, LCP, TBT, CLS, server response, page weight and requests, with the best site in every row marked. Each column links to its full report.
    • Bulk PageSpeed checker: up to 50 URLs a day through Google PageSpeed Insights, mobile or desktop, with lab metrics, Chrome UX Report data and the biggest fix per page, sortable, filterable and as CSV.
  4. Three headless tools: JavaScript SEO, unused code, responsive screens and a CSP generator

    • JS rendering check: the HTML your server sends next to the page after JavaScript runs, field by field. It flags text, links and structured data that only exist after scripts run, and a canonical or noindex that JavaScript changes.
    • Unused CSS and JavaScript: Chromium code coverage for every script and stylesheet, with the unused share per file and third parties marked, next to the savings Google estimates.
    • Responsive check and CSP generator: screenshots at 360, 414, 768, 1024 and 1440 px, the element that makes a page scroll sideways, tiny text and small tap targets, and a Content-Security-Policy built from what the page actually loaded, inline scripts hashed.
    • Every report now includes these measurements: two new SEO checks for JavaScript rendering and a best-practices check for sideways scrolling.
  5. Thirty more guides: platforms, previews, trust signals and the 200 mark

    • Platforms: Cloudflare settings, Netlify and Vercel headers, Nginx and Apache configurations for an A grade, Caddy, Joomla and Drupal basics, Magento performance.
    • Social and structured data: Facebook App ID, debugging a cached preview, previews for PDF and file links, og:title, description and type; validating schema without Google's tools, schema for multilingual sites, structured navigation for large sites.
    • Accessibility and workflows: accessibility statements, the European Accessibility Act, alt text decisions; measuring before and after a redesign, picking which fixes to do first, a quarterly SEO review template.
    • Best practices and security: custom 404 pages, privacy policy and contact links, a cookie banner that passes, GA4 and Tag Manager cost, console errors and deprecated APIs, HTML validation errors, Safe Browsing flags, certificate chain errors, Lighthouse score vs Core Web Vitals, internal links that redirect. 206 guides in total.
  6. Thirty more guides: WordPress hosting and caching, hacked sites, speed, technical SEO

    • WordPress: LiteSpeed Cache and WP Rocket settings for Core Web Vitals, security headers without a plugin, choosing a host by measured TTFB, page builders vs Gutenberg, multilingual WordPress with WPML and Polylang, the WordPress migration checklist, staging with host tools and plugins.
    • Security: recovering a hacked WordPress site, the Japanese keyword hack, pharma and casino spam injections, Subresource Integrity, rate limiting and bot protection, backups that actually restore.
    • Speed: image CDNs, service workers and offline pages, system fonts vs web fonts, Core Web Vitals for news sites, speed budgets in CI.
    • Technical SEO and workflows: crawl budget for small sites, subfolder vs subdomain vs ccTLD, cross-domain canonicals, tracking parameters and canonicals, "Discovered - currently not indexed", Search Console vs getReport.
    • Accessibility and structured data: accessible tables, accessible modals and dialogs, motion and prefers-reduced-motion, Event schema, Recipe schema. 176 guides in total.
  7. Thirty more guides: platforms, WordPress settings, workflows and technical SEO

    • Titles and descriptions: page titles that rank and get clicked; meta description length, wording and Google rewrites.
    • WordPress: the Yoast SEO and Rank Math settings we recommend, Elementor and Divi performance settings, WooCommerce product schema, image optimisation plugins compared, WP-Cron and scheduled tasks.
    • Platforms: what you can and cannot fix on Shopify, Wix, Squarespace and Webflow; headers and caching for static sites (Hugo, Astro, Next.js).
    • Workflows: a monthly site health routine, an agency workflow with one report per client per month, writing a ticket a developer can act on, explaining a score to a client, staging sites without getting them indexed.
    • Speed and technical SEO: critical CSS in 2026, video on landing pages, Core Web Vitals for e-commerce, reading a waterfall chart and a filmstrip, orphan pages, redirect chains after a migration, 404 vs 410 vs redirect, the site migration checklist, faceted navigation, soft 404s. 146 guides in total.
  8. Thirty more guides: security, accessibility, structured data, social and WordPress

    • Security: Referrer-Policy, Permissions-Policy, Server and X-Powered-By headers, CORS wildcards, certificate expiry, TLS 1.0/1.1, security.txt, directory listings and exposed files, outdated CMS versions, WordPress security without a plugin.
    • Accessibility: link and button names, landmarks and skip links, focus order and keyboard traps, zoom and viewport, target size, language attributes.
    • Structured data and social: Article and BlogPosting, FAQ and HowTo after Google's changes, LocalBusiness, BreadcrumbList, duplicate entities; Twitter/X cards, og:url and canonical, previews in WhatsApp, Slack, LinkedIn and iMessage, generating OG images.
    • WordPress: duplicate SEO plugins, two caching plugins, abandoned and closed plugins, WooCommerce cart fragments and cart/checkout caching. 116 guides in total.
  9. Thirty more guides

    • Speed: web fonts without layout shift, WebP and AVIF, srcset and sizes, third-party scripts, DOM size, long tasks, resource hints, Speed Index and FCP, field vs lab data, mobile vs desktop scores, CDN basics, server response time on shared hosting.
    • Technical SEO: trailing slashes and www, URL structure, internal links, nofollow and sponsored, image alt text, thin content, duplicate titles, favicons, breadcrumbs, pagination, AMP, JavaScript-rendered content, hreflang in sitemaps and x-default, sitemap index files and lastmod, robots.txt patterns; plus the framing and nosniff headers.
    • Every guide has a screenshot from a real run of the tool it explains; code samples in guides are now keyboard-scrollable.
  10. Server log analyser, WordPress fix recipes and the page-builder check

    • Server log analyser: drop an Apache, Nginx, IIS or JSON access log (gzipped too) and see every bot, its hits per day, the URLs and 404s it fetches, how much of Googlebot's crawl went to redirects and parameter URLs, which AI crawlers read your content, and whether the Googlebot in your log is real. The file is processed in your browser and never uploaded; only the addresses you ask to verify go to our server.
    • WordPress fix recipes: when a report detects WP Rocket, LiteSpeed Cache, W3 Total Cache, Autoptimize, Yoast SEO, Rank Math, Elementor or WooCommerce, the findings show the exact screens and settings to change in that plugin, with the version the steps were verified on.
    • Page-builder weight: how much of a page's code and markup comes from Elementor, Divi, WPBakery, Bricks, Oxygen or Beaver Builder, and which of the builder's performance settings to switch on.
    • One more guide: your server logs, decoded.
  11. Core Web Vitals history and bulk URL checker

    • Core Web Vitals history: 40 weeks of real Chrome-user data for any site Google publishes it for, one chart per metric (LCP, INP, CLS, FCP, TTFB) against the good / needs-improvement / poor bands, the share of good visits, phone or desktop, whole site or one page, and the numbers as a table.
    • Bulk URL checker: paste up to 1,000 URLs and get the status after redirects, the final URL, the redirect chain and its type, time to first byte, content type, title, canonical and noindex for every one, with filters, a permanent run link and a CSV download. Private addresses are skipped by the safety guard; at most four requests at a time per host.
    • Two more guides: reading 40 weeks of Core Web Vitals history, and bulk URL checking for migrations.
  12. Cookie & consent scanner and WooCommerce checker

    • Cookie & consent scanner: every report now records the cookies and trackers a first-time visitor gets before touching the banner, clicks the banner's accept button (18 consent platforms, 20 languages) and records what changed. Four new checks: trackers before consent, cookies before consent, a reject option on the first layer, cookie lifetimes over 13 months.
    • WooCommerce checker: cart fragments on non-cart pages, a cart or checkout served from a page cache, Product schema without price, availability or rating, and out-of-stock products left indexable.
    • Two more guides: cookies before consent, and the WooCommerce checklist.
  13. AI crawler check and hacked site checker

    • AI crawler readiness check: which of 18 AI user agents (GPTBot, ClaudeBot, PerplexityBot, Google-Extended and more) your robots.txt allows, grouped by purpose; whether you have an llms.txt and if it follows the llmstxt.org format; noai and TDM opt-out signals.
    • Hacked site checker: the page is fetched as a visitor, as Googlebot and as a visitor from Google, and the copies are compared. Injected text, pharma and casino links, hidden links, foreign-script keyword spam and Google-only redirects are reported with evidence. Four new security checks run on every report.
    • Seven more guides, including the pre-launch checklist and the indexability checklist.
  14. Guides

    • A new Guides section: long-form, screenshot-backed guides that go beyond the /learn pages, with copy-paste configs for nginx, Apache, Caddy, Cloudflare and WordPress. The first 42 cover Core Web Vitals, technical SEO, security headers, accessibility, structured data, social previews and the WordPress rookie mistakes.
    • Every tool page lists its guides and every guide ends with the form, so a guide is never a dead end. Guides are written in Markdown with tool and check cards generated from the check catalogue, so their advice cannot drift from what the report says.
  15. WordPress Doctor (wave 1)

    • Reports of WordPress sites get a WordPress Doctor panel: detected theme, builder and plugins, the rookie-mistakes scan ("you made 4 of 8"), the cost of every plugin on the page, duplicate SEO, cache and schema plugins, and abandoned or closed plugins from the wordpress.org directory.
    • "Send to my developer": a fixes-only view of any report with a Markdown checklist and a Trello/Jira CSV export.
    • Two WordPress tools: health check and plugin detector.
  16. Six more tools (wave 2a)

    • Canonical checker, hreflang checker with return-link verification, XML sitemap validator with sampled status checks, HTTP/2 and HTTP/3 test, broken link checker (150 links, internal and external) and image size checker (100 images with real dimensions).
    • Nine new checks behind them: sitemap validity, sampled sitemap URLs, page in sitemap, hreflang return links and reachability, redirecting links, HTTP/2 negotiation, HTTP/3, heavy, oversized, unsized and broken images.
  17. Launch pack (M4)

    • Funding page with live totals from Ko-fi, GitHub Sponsors and Stripe, the unlock ladder and the supporters wall.
    • Donate page, thank-you page with a supporter badge.
    • Honest comparisons with GTmetrix, Pingdom, Semrush, SEOptimer and WebPageTest.
    • About, privacy, terms, crawler and status pages; this changelog.
    • Cookie-free analytics (Plausible, loaded only when configured); a nonce-based Content-Security-Policy.
    • Production images, one-command deploy, nightly backups, retention job.
  18. Exports, guides and tools (M3)

    • PDF export, OG image and score badge for every report.
    • Module tabs on desktop, accordion on mobile, deep links to modules and findings.
    • History strip when a domain has earlier reports; feedback thumbs stored.
    • Every passing check now reads as a goal met, not a failure.
    • 99 learn guides generated from the check catalogue; twelve single-purpose tools.
    • The Dial: new logo, favicons and social covers.
  19. Speed and rendering (M2)

    • Google PageSpeed Insights and Chrome UX Report field data, with a local Lighthouse fallback.
    • Chromium rendering: screenshot, console errors, request waterfall, axe-core accessibility scan, tech detection.
    • All seven modules live: speed, SEO, security, accessibility, structured data, social, best practices.
  20. First reports (M1)

    • Fetch pipeline behind the SSRF guard, 81 HTML checks, scoring and the live report page.
    • Report cache (12 hours), rate limits and Turnstile.
  21. Skeleton (M0)

    • Monorepo, design tokens, fixtures with 20 deliberately broken pages, CI.