Guides · Transparency

Everything AegorIQ checks, and why it matters

The complete list. Not a summary, not a highlights reel. Every check we run on an Australian small-business website, what it's actually looking for, and what it means if it fails. Plus, just as importantly, what we don't check.

There's a reason most website scanners don't publish this list: it invites scrutiny. A vague promise of "comprehensive security scanning" is much easier to sell than an itemised account of exactly what you do and don't look at.

We'd rather be scrutinised. If you're going to trust a report about your own business, you should be able to see precisely what produced it, before you pay for anything. Every check below runs against your live website. If a check can't complete, we tell you it wasn't tested. We never fill a gap with a plausible guess.

36
Scorecard · free
The free Scorecard runs the same 36 checks as Essentials. You get the count: how many issues, and how serious. Not which ones.
36
Essentials · $79
The same 36 checks, but every issue named (what it is, where it is, why it matters) plus a read of your policies.
52
Deep Scan · $149
All of the above, plus the 16 deeper checks below. No human review and no prioritised roadmap, those are Expert.
52
Expert · $497
All 52 checks, plus a human review, step-by-step fixes, a prioritised roadmap and a 45-minute call.
Every finding is the output of a specific, repeatable check. Run the same scan twice on an unchanged site and you get the same answer. No AI writes your findings.

Security

The things an attacker would look for, and the configuration mistakes that quietly leave the door open.

01

SSL certificate & HTTPS

Whether your site is served over a valid encrypted connection. Without it, anything a customer types travels in the clear and browsers label you "Not secure".

All tiers
02

Security headers

Five browser-level protections (HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) that defend visitors against clickjacking and code injection.

All tiers
03

SPF record

Whether you've declared who is allowed to send email as your business. Without it, anyone can.

All tiers
04

DKIM signing

Whether your outgoing email is cryptographically signed, so recipients can verify it genuinely came from you.

All tiers
05

DMARC record and enforcement level

Whether you have a policy telling receivers what to do with spoofed mail, and critically, whether it's actually enforced or merely monitoring.

All tiers
06

Duplicate SPF / DMARC records

The misconfiguration almost nobody checks. Publish two DMARC records and receivers ignore DMARC entirely, so you look protected while anyone can spoof you. We've found this on live Australian businesses that believed they were covered.

All tiers
07

Malware & phishing blacklist

Whether Google has flagged your site as unsafe. If it has, most visitors never get past the red warning screen.

All tiers
08

Known software vulnerabilities

WordPress core, plugins and themes checked against a live vulnerability feed. Out-of-date components are the single most common way small-business sites get hacked.

All tiers
09

Payment handling

Whether your checkout uses a recognised hosted payment provider, keeping card data off your own servers and reducing your PCI burden.

All tiers
10

Domain registration expiry : not possible for .au

When your domain lapses. An expired domain takes your website and your email offline, and can be bought by someone else.

The honest catch: we cannot perform this check on a .au domain, and neither can anyone else. Under auDA's WHOIS Policy (clause 4.5) expiry and renewal dates are deliberately withheld from the .au registry, scrapers were harvesting them to send registrants fake renewal notices. Since almost every site we scan is a .au domain, this check will usually come back as "not tested", and we'll show you how to check it yourself in about two minutes. We'd rather tell you that here than let you find out after you've paid.

All tiers
11

Registrar transfer lock

A free setting that stops your domain being transferred away after a credential leak, one of the most common hijacking routes.

All tiers
12

DNSSEC

Whether your DNS answers are cryptographically signed, so attackers can't forge them and silently redirect your visitors or your mail.

All tiers

Privacy

This is where we stop counting records and start reading.

13

Privacy policy: present

Whether you have one at all. For any business collecting personal information, it's a direct legal requirement.

All tiers
14

Privacy policy,depth

We open your actual policy and check it against the five elements the Australian Privacy Principles expect: what you collect, whether it goes to third parties or overseas, how it's stored, how someone makes a complaint, and a last-updated date. We name the ones that are missing. Almost nothing else on the market does this.

All tiers
15

Cookie-consent notice

Whether visitors are told about tracking before it happens.

All tiers
16

Analytics & tracking detection

Which advertising and analytics tools are actually running on your site: named, not just counted.

All tiers
17

Region-aware consent requirements

If you tell us you have EU or UK customers, we apply their rules: non-essential cookies must not load until the visitor actively opts in. Australian businesses selling overseas routinely miss this.

All tiers
18

Customer accounts & login credentials

Whether your site lets customers create an account and sign in. Holding logins is normal and is not a fault, but it changes what a breach means, because people reuse passwords. We explain what the Notifiable Data Breaches scheme then asks of you.

All tiers

Australian consumer law & business identity

19

Terms & Conditions

Whether you've published the contract that governs every sale you make.

All tiers
20

Returns & refund policy: present

What the Australian Consumer Law expects when you sell goods or services.

All tiers
21

Refund wording: read against the ACL

We read your terms and refund pages for blanket "no refunds" and "all sales are final" statements. Consumer guarantees can't be excluded, so these can be unlawful: and the ACCC actively enforces against them. We flag the exact wording for professional review. We never make a legal determination. An automated scan doesn't get to do that.

All tiers
22

Shipping / delivery policy

For online stores: whether customers can see delivery times, costs and areas served before they buy.

All tiers
23

ABN / business identity

Whether customers and B2B partners can verify you're a real registered business.

All tiers
24

Business address visible

A basic transparency signal. Its absence raises legitimacy questions and costs conversions.

All tiers
25

Contact details reachable

Whether there is any visible way to reach you, contact page, phone, or email.

All tiers
26

Marketing consent quality (Spam Act)

Whether your sign-up boxes are pre-ticked. Under the Spam Act, consent must be an active choice, a pre-ticked box isn't valid consent, which can make your whole marketing list unlawfully collected.

All tiers

Performance & experience

27

Broken links

We crawl your pages and test the links. Every broken one is a dead end for a customer, and a signal to Google that the site isn't maintained.

All tiers
28

Mobile-friendliness

Whether your pages are built to display properly on a phone, where most of your traffic actually is.

All tiers
29

Content freshness

Whether your site looks current or is quietly showing its age, an out-of-date copyright year, or old events still listed as upcoming. A brand-and-trust signal, not a fault; shown for your awareness.

All tiers
30

Placeholder & template content

Whether your site still carries a website builder’s defaults (unrenamed template pages (like /about-harris or /new-page-2), or placeholder text and headings (“Lorem ipsum”, “XXXX”)) which read to a visitor as “half-built” and quietly cost you credibility.

All tiers

AI Readiness

Six on-page signals showing how ready your site is for AI assistants (ChatGPT, Perplexity, Google’s AI answers) to discover and understand your business. Informational. It does not affect your TrustScore.

31

AI crawler access

Whether your robots.txt allows the AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot) to read your site. Blocking them is a legitimate choice, we report it neutrally, never as a fault.

All tiers
32

Readable without JavaScript

Most AI crawlers do not run JavaScript, so a site built entirely in the browser is invisible to them. We check whether your content is in the initial HTML.

All tiers
33

Structured data (Schema.org)

The machine-readable summary AI assistants and search engines use to understand your business correctly, instead of guessing from your page text.

All tiers
34

Machine-readable business identity

Whether your name, contact details and identifiers are present in a form an AI can extract and cross-check.

All tiers
35

Preview & summary metadata

Meta description and Open Graph tags, the short summary AI and social platforms use to represent your page.

All tiers
36

Agent-navigability

Whether an AI agent acting for a customer could find its way around your site. Expert adds a tailored AI Readiness action plan, including the off-site factors a scan alone cannot fix.

All tiers

Deep scans: Expert only

Fourteen further checks that go beneath the surface of the site, plus a human being who reads the result.

37

Exposed sensitive files

Config files, backups, repository data and admin endpoints that should not be publicly reachable. Attackers scan for exactly these.

Deep Scan & Expert
38

Directory listing

Whether a stranger can browse and download every file in a folder just by visiting it,“not linked” is not the same as “not public”.

Deep Scan & Expert
39

WordPress XML-RPC exposure

Whether the legacy endpoint that lets attackers try hundreds of passwords in one request (and amplify attacks on your site) is left switched on.

Deep Scan & Expert
40

Leaked API keys & secrets

Credentials accidentally shipped in your website’s JavaScript, where anyone can read them.

Deep Scan & Expert
41

Exposed backup & config files

Backups or config files left in the web root, often containing database credentials or a full copy of your site.

Deep Scan & Expert
42

Payment-skimming surface (script integrity)

Third-party scripts loading without integrity checks. If one of those providers is compromised, malicious code runs on your checkout, and you would never see it in your own code.

Deep Scan & Expert
43

Insecure cookies

Session cookies missing the Secure and HttpOnly flags, making them easier to steal and hijack a logged-in session.

Deep Scan & Expert
44

Subdomain takeover risk

Subdomains pointing at services you no longer own: which an attacker can claim and use to phish your customers from your own domain.

Deep Scan & Expert
45

Exposed non-production subdomains

Dev, staging and admin subdomains that are publicly discoverable and usually far less protected than production.

Deep Scan & Expert
46

Exposed service ports

A safe, limited check for admin and database ports that should not be reachable from the open internet.

Deep Scan & Expert
47

TLS / encryption strength

Whether your server still accepts outdated, insecure protocol versions that fail modern standards.

Deep Scan & Expert
48

Mixed content

Insecure resources loading on otherwise-secure pages, weakening the padlock.

Deep Scan & Expert
49

Advanced email security (MTA-STS, TLS-RPT)

The layer beyond SPF/DKIM/DMARC: enforcing encrypted mail delivery and reporting when it fails.

Deep Scan & Expert
50

Performance & SEO (Google Lighthouse)

Full performance and SEO scoring with Core Web Vitals: how fast your site really is, and how well search engines can read it.

Deep Scan & Expert
51

Admin sign-in exposure & MFA signals

Whether your admin login is reachable from the open internet, whether it hands off to a single-sign-on provider, and whether a two-factor plugin is visible from outside. Read-only, we never submit a login form. MFA itself is an account setting we cannot see from outside, and the finding says so plainly.

Deep Scan & Expert
52

Accessibility barriers (WCAG 2.2 AA: automated)

Colour contrast, missing image alt text and unlabelled form fields, each barrier named with the number of elements affected. An automated check finds common barriers; it is not a WCAG conformance assessment, and the finding says so.

Deep Scan & Expert
,

A human review

Every Expert report is read by a cybersecurity professional before it reaches you. They tell you which two findings actually matter this month, and which can wait. That judgement is the one thing no scanner can automate.

Expert

What we don't check

This section matters more than the list above. Any company can tell you what it does. Overclaiming is how this industry lost people's trust, so here are our limits, stated plainly.

  • This is not a penetration test. We don't attack your site, exploit anything, or attempt to break in. A real penetration test costs thousands and is a different exercise entirely. Anyone selling you one for a few hundred dollars is not selling you one.
  • We don't log in. We check what's publicly visible. We never authenticate into your site, admin panel or database, so vulnerabilities that only exist behind a login are outside what we can see.
  • We don't touch your customer data. We never read your database, your orders or your customer records. We don't want them and we don't have them.
  • We don't give legal advice. When something is a legal judgement (like whether your refund wording breaches the ACL): we flag it for professional review. We tell you what we found and why it's worth a lawyer's eye. We don't rule on it.
  • We can't always read a JavaScript-heavy site. Some sites build their content in the browser. When we can't reliably read yours, we say so and mark the scan as limited, rather than reporting things as "missing" when we simply couldn't see them.
  • We never scan without permission. Every scan requires you to confirm you own the site or are authorised to check it. We don't scan uninvited, and we will never email you out of the blue to say your website has problems.
  • We don’t certify accessibility. Our Expert report runs an automated accessibility check and names the barriers it finds, colour contrast, missing image alt text, unlabelled form fields. Automated testing catches roughly a third of WCAG 2.2 AA. It cannot judge keyboard operability, screen-reader flow, or whether your alt text is meaningful, so it is a starting point and never a conformance verdict. Anyone selling “automated WCAG compliance” is selling something that does not exist, the US Federal Trade Commission fined a vendor US$1 million over that claim in January 2025.

That's the whole picture. If a check isn't on this list, we don't run it, and we won't imply we did.

See it applied

Now see what a real report looks like.

Read a full Expert report before you spend anything, or run a free Scorecard and find out how many of these checks your own site passes.