See what is broken
on your site.
Paste one code snippet into your site. We scan it for SEO, speed, security and accessibility, and show you who really visits it: people or bots.
Overall score
Sample report.
Three steps. No installs.
Add your site
Enter the domain and get a short code that is unique to your account.
Put the code on your site
Paste it into the page or into a Custom HTML tag in Google Tag Manager. That is how you prove the site is yours.
Get your report
Scanning starts only once the code is verified. Problems are sorted by how much they matter.
Everything that matters in one report.
Technical SEO
Titles, descriptions, canonical tags, robots.txt, sitemap, redirects and everything that keeps Google from finding you.
- Meta description missing on 3 pages
- Two H1 headings on the home page
- Canonical missing on /products
Real speed
Core Web Vitals measured on your own visitors, not just in a lab test.
Broken links
We find the pages that return errors before your visitors do.
Structured data
We check JSON-LD and schema.org so Google understands what you offer and can show rich results.
Security
HTTPS, security headers, cookies and mixed content.
Accessibility
Images without descriptions, forms without labels, buttons without names.
People or bots?
Now you can tell.
The same snippet separates real visitors from bots and from verified crawlers such as Googlebot, without relying on the user agent.
People or bots
We separate real visitors from automated browsers and scrapers by technical signals, not by user agent.
Spam bots
We spot spam bots by sessions of a few seconds with no interaction, bursts of visits from the same network and automated browsers, and keep them out of your statistics.
Fake clicks from Google Ads
We find ad clicks that come from bots and prepare the evidence (GCLID, time, network) for the Google Ads form, plus the list of safe networks to exclude, so they stop draining your budget. Guide ›
iOS and Android apps
A small SDK for React Native and Expo records sessions, screens and installs, with our own algorithm that detects fake phones. Native apps send the same JSON directly. Guide ›
JS errors, grouped human vs bot
We catch errors from your site and app automatically, with a stack trace and the steps before, grouped by the same bug. Unlike other tools, you see right away how many real people were affected, not just a total inflated by bots.
Verified crawlers
Googlebot and Bing are confirmed through DNS and AI crawlers through their official IP lists, not by name.
Phone farms
We use our own algorithm to detect a fake phone accessing the client's site, a trick used for fake traffic and installs.
Sources and referrals
See where visitors come from: ref and utm parameters, Google, social networks or direct visits.
One snippet, anywhere
Paste it into the page or into a Custom HTML tag in Google Tag Manager. No third-party account, no installs.
Read the guide: fake clicks in Google Ads ›
Sample breakdown.
Easy to use. Hard to misuse.
We scan only your site
Scanning starts once our snippet is installed on your site, in the page or through Google Tag Manager. That is how we know the site is yours.
Sign in your way
With Google, Apple, or email and password. The first time you use email you choose your password.
Password reset by code
Forgot your password? You get a code by email and choose a new one. Other devices are signed out.
Romanian and English
The site, reports and emails come in Romanian or English, and you can switch any time in Settings.
Frequently asked questions
How do I prove the site is mine?
Put our snippet in the page or in a Custom HTML tag in Google Tag Manager and press Verify. If we find it on the site, we know it is yours. We only scan verified sites.
How much does it cost?
The account is free.
Does it work with Google Tag Manager?
Yes. Paste the snippet into a Custom HTML tag and fire it on all pages. Publish the container, press Verify, and we see the page the way a browser does.
What data does the snippet collect?
The visited page, the source, clicks, scrolling, Core Web Vitals, the browser type, the country and the IP network prefix. We do not store the full IP address and we do not read form values.
How do you tell people from bots?
We combine technical browser signals, on-page behaviour and DNS verification of known crawlers such as Googlebot and Bing, instead of relying on the user agent alone.
What are spam bots?
Bots that visit sites or submit forms in bulk with no real intent: sessions of a few seconds, zero interaction, the same network again and again. We flag them separately so they do not skew your statistics.
Can I see fake clicks from Google Ads?
Yes. For visits from ads we give you a report with the GCLID, time and network, plus the list of safe networks to exclude. The Google Ads administrator submits the form, and the decision belongs to Google.
Do you catch errors, like Sentry?
Yes, automatically, on the web and in the app: message, stack trace, steps before, grouped by the same bug. What is different: every error already comes labelled human or bot, so you never mistake a real bug for noise from an emulator. What we do not do yet: we do not unminify stack traces (source maps) and we do not catch native crashes (Obj-C/Kotlin), only JavaScript errors.
Does it work for iOS and Android apps?
Yes. Add the app in the dashboard, install the SDK for React Native or Expo, and see sessions, screens, installs and bots. Native apps send the same JSON straight to the collector.
Does scanning slow my site down?
No. We scan through the Cloudflare network with page and frequency limits, and the snippet on your site is small and loads asynchronously.
Ready in minutes.
The account is free. We only scan sites you have proven you own.
Sign in with Google, Apple or with email and password.