Free EU compliance scan for any website.

Not just WordPress. Enter your URL and instantly check HTTPS security, cookie consent, privacy-policy links, forms, and security headers — on WordPress, Shopify, Webflow, Next.js, Squarespace, Wix, or hand-written HTML.

Try it:

Need documented proof — not just flags?

The Pro tier turns findings into auditor-ready PDF reports, DPA documents, NIS2 vendor clauses, and accessibility statements you can forward to clients, auditors and insurers.

See Pro — $79/year ↓ WordPress plugin (free)

What the scan checks

Six automated checks based on EU requirements that apply to every website serving EU users — regardless of platform. Plus DORA resilience signals for financial and ICT entities.

🔒 HTTPS + HSTS

TLS and Strict-Transport-Security. GDPR Art. 32 requires appropriate technical security measures.

🍪 Cookie consent

Detects 15+ consent platforms in served HTML (Cookiebot, OneTrust, CookieYes…). ePrivacy Directive requires prior consent.

📋 Forms & privacy link

Forms found without a visible privacy-policy link are a top GDPR enforcement target (Art. 13).

📄 Legal pages

Privacy policy, imprint, terms, and EAA accessibility statement linked from your homepage.

🛡️ Security headers

CSP, X-Content-Type-Options, Referrer-Policy, frame protection — OWASP baseline, NIS2 Art. 21.

🔍 Platform fingerprint

Identifies your CMS/stack so advice is relevant. Purely informational — nothing is stored.

🏦 DORA resilience

DORA (EU 2022/2554) effective Jan 2025. Checks for incident reporting, business continuity, ICT risk management and resilience testing disclosures on financial/ICT entity sites.