Not just WordPress. Enter your URL and instantly check HTTPS security, cookie consent, privacy-policy links, forms, and security headers — on WordPress, Shopify, Webflow, Next.js, Squarespace, Wix, or hand-written HTML.
The Pro tier turns findings into auditor-ready PDF reports, DPA documents, NIS2 vendor clauses, and accessibility statements you can forward to clients, auditors and insurers.
See Pro — $79/year ↓ WordPress plugin (free)Six automated checks based on EU requirements that apply to every website serving EU users — regardless of platform. Plus DORA resilience signals for financial and ICT entities.
TLS and Strict-Transport-Security. GDPR Art. 32 requires appropriate technical security measures.
Detects 15+ consent platforms in served HTML (Cookiebot, OneTrust, CookieYes…). ePrivacy Directive requires prior consent.
Forms found without a visible privacy-policy link are a top GDPR enforcement target (Art. 13).
Privacy policy, imprint, terms, and EAA accessibility statement linked from your homepage.
CSP, X-Content-Type-Options, Referrer-Policy, frame protection — OWASP baseline, NIS2 Art. 21.
Identifies your CMS/stack so advice is relevant. Purely informational — nothing is stored.
DORA (EU 2022/2554) effective Jan 2025. Checks for incident reporting, business continuity, ICT risk management and resilience testing disclosures on financial/ICT entity sites.