Guides · Transparency

Everything AegorIQ checks — and why it matters

The complete list. Not a summary, not a highlights reel — every check we run on an Australian small-business website, what it's actually looking for, and what it means if it fails. Plus, just as importantly, what we don't check.

There's a reason most website scanners don't publish this list: it invites scrutiny. A vague promise of "comprehensive security scanning" is much easier to sell than an itemised account of exactly what you do and don't look at.

We'd rather be scrutinised. If you're going to trust a report about your own business, you should be able to see precisely what produced it — before you pay for anything. Every check below runs against your live website. If a check can't complete, we tell you it wasn't tested. We never fill a gap with a plausible guess.

35
Scorecard · free
The free Scorecard runs the same 35 checks as Essentials — you get the count: how many issues, and how serious. Not which ones.
35
Essentials · $197 $109
The same 35 checks, but every issue named — what it is, where it is, why it matters — plus a human review of your policies.
49
Expert · $497 $309
All of the above, plus 14 deeper checks, step-by-step fixes, and a full human review.
Every finding is the output of a specific, repeatable check. Run the same scan twice on an unchanged site and you get the same answer. No AI writes your findings.

Security

The things an attacker would look for, and the configuration mistakes that quietly leave the door open.

01

SSL certificate & HTTPS

Whether your site is served over a valid encrypted connection. Without it, anything a customer types travels in the clear and browsers label you "Not secure".

All tiers
02

Security headers

Five browser-level protections (HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) that defend visitors against clickjacking and code injection.

All tiers
03

SPF record

Whether you've declared who is allowed to send email as your business. Without it, anyone can.

All tiers
04

DKIM signing

Whether your outgoing email is cryptographically signed, so recipients can verify it genuinely came from you.

All tiers
05

DMARC record and enforcement level

Whether you have a policy telling receivers what to do with spoofed mail — and critically, whether it's actually enforced or merely monitoring.

All tiers
06

Duplicate SPF / DMARC records

The misconfiguration almost nobody checks. Publish two DMARC records and receivers ignore DMARC entirely — so you look protected while anyone can spoof you. We've found this on live Australian businesses that believed they were covered.

All tiers
07

Malware & phishing blacklist

Whether Google has flagged your site as unsafe. If it has, most visitors never get past the red warning screen.

All tiers
08

Known software vulnerabilities

WordPress core, plugins and themes checked against a live vulnerability feed. Out-of-date components are the single most common way small-business sites get hacked.

All tiers
09

Payment handling

Whether your checkout uses a recognised hosted payment provider, keeping card data off your own servers and reducing your PCI burden.

All tiers
10

Domain registration expiry — not possible for .au

When your domain lapses. An expired domain takes your website and your email offline — and can be bought by someone else.

The honest catch: we cannot perform this check on a .au domain, and neither can anyone else. Under auDA's WHOIS Policy (clause 4.5) expiry and renewal dates are deliberately withheld from the .au registry — scrapers were harvesting them to send registrants fake renewal notices. Since almost every site we scan is a .au domain, this check will usually come back as "not tested", and we'll show you how to check it yourself in about two minutes. We'd rather tell you that here than let you find out after you've paid.

All tiers
11

Registrar transfer lock

A free setting that stops your domain being transferred away after a credential leak — one of the most common hijacking routes.

All tiers
12

DNSSEC

Whether your DNS answers are cryptographically signed, so attackers can't forge them and silently redirect your visitors or your mail.

All tiers

Privacy

This is where we stop counting records and start reading.

13

Privacy policy — present

Whether you have one at all. For any business collecting personal information, it's a direct legal requirement.

All tiers
14

Privacy policy — depth

We open your actual policy and check it against the five elements the Australian Privacy Principles expect: what you collect, whether it goes to third parties or overseas, how it's stored, how someone makes a complaint, and a last-updated date. We name the ones that are missing. Almost nothing else on the market does this.

All tiers
15

Cookie-consent notice

Whether visitors are told about tracking before it happens.

All tiers
16

Analytics & tracking detection

Which advertising and analytics tools are actually running on your site — named, not just counted.

All tiers
17

Region-aware consent requirements

If you tell us you have EU or UK customers, we apply their rules: non-essential cookies must not load until the visitor actively opts in. Australian businesses selling overseas routinely miss this.

All tiers

Australian consumer law & business identity

18

Terms & Conditions

Whether you've published the contract that governs every sale you make.

All tiers
19

Returns & refund policy — present

What the Australian Consumer Law expects when you sell goods or services.

All tiers
20

Refund wording — read against the ACL

We read your terms and refund pages for blanket "no refunds" and "all sales are final" statements. Consumer guarantees can't be excluded, so these can be unlawful — and the ACCC actively enforces against them. We flag the exact wording for professional review. We never make a legal determination — an automated scan doesn't get to do that.

All tiers
21

Shipping / delivery policy

For online stores: whether customers can see delivery times, costs and areas served before they buy.

All tiers
22

ABN / business identity

Whether customers and B2B partners can verify you're a real registered business.

All tiers
23

Business address visible

A basic transparency signal. Its absence raises legitimacy questions and costs conversions.

All tiers
24

Contact details reachable

Whether there is any visible way to reach you — contact page, phone, or email.

All tiers
25

Marketing consent quality (Spam Act)

Whether your sign-up boxes are pre-ticked. Under the Spam Act, consent must be an active choice — a pre-ticked box isn't valid consent, which can make your whole marketing list unlawfully collected.

All tiers

Performance & experience

26

Broken links

We crawl your pages and test the links. Every broken one is a dead end for a customer, and a signal to Google that the site isn't maintained.

All tiers
27

Mobile-friendliness

Whether your pages are built to display properly on a phone, where most of your traffic actually is.

All tiers
28

Content freshness

Whether your site looks current or is quietly showing its age — an out-of-date copyright year, or old events still listed as upcoming. A brand-and-trust signal, not a fault; shown for your awareness.

All tiers
29

Placeholder & template content

Whether your site still carries a website builder’s defaults — unrenamed template pages (like /about-harris or /new-page-2), or placeholder text and headings (“Lorem ipsum”, “XXXX”) — which read to a visitor as “half-built” and quietly cost you credibility.

All tiers

AI Readiness

Six on-page signals showing how ready your site is for AI assistants (ChatGPT, Perplexity, Google’s AI answers) to discover and understand your business. Informational — it does not affect your TrustScore.

30

AI crawler access

Whether your robots.txt allows the AI crawlers (GPTBot, ClaudeBot, Google-Extended, PerplexityBot) to read your site. Blocking them is a legitimate choice — we report it neutrally, never as a fault.

All tiers
31

Readable without JavaScript

Most AI crawlers do not run JavaScript, so a site built entirely in the browser is invisible to them. We check whether your content is in the initial HTML.

All tiers
32

Structured data (Schema.org)

The machine-readable summary AI assistants and search engines use to understand your business correctly, instead of guessing from your page text.

All tiers
33

Machine-readable business identity

Whether your name, contact details and identifiers are present in a form an AI can extract and cross-check.

All tiers
34

Preview & summary metadata

Meta description and Open Graph tags — the short summary AI and social platforms use to represent your page.

All tiers
35

Agent-navigability

Whether an AI agent acting for a customer could find its way around your site. Expert adds a tailored AI Readiness action plan, including the off-site factors a scan alone cannot fix.

All tiers

Deep scans — Expert only

Fourteen further checks that go beneath the surface of the site, plus a human being who reads the result.

36

Exposed sensitive files

Config files, backups, repository data and admin endpoints that should not be publicly reachable. Attackers scan for exactly these.

Expert
37

Directory listing

Whether a stranger can browse and download every file in a folder just by visiting it — “not linked” is not the same as “not public”.

Expert
38

WordPress XML-RPC exposure

Whether the legacy endpoint that lets attackers try hundreds of passwords in one request — and amplify attacks on your site — is left switched on.

Expert
39

Leaked API keys & secrets

Credentials accidentally shipped in your website’s JavaScript, where anyone can read them.

Expert
40

Exposed backup & config files

Backups or config files left in the web root — often containing database credentials or a full copy of your site.

Expert
41

Payment-skimming surface (script integrity)

Third-party scripts loading without integrity checks. If one of those providers is compromised, malicious code runs on your checkout — and you would never see it in your own code.

Expert
42

Insecure cookies

Session cookies missing the Secure and HttpOnly flags, making them easier to steal and hijack a logged-in session.

Expert
43

Subdomain takeover risk

Subdomains pointing at services you no longer own — which an attacker can claim and use to phish your customers from your own domain.

Expert
44

Exposed non-production subdomains

Dev, staging and admin subdomains that are publicly discoverable and usually far less protected than production.

Expert
45

Exposed service ports

A safe, limited check for admin and database ports that should not be reachable from the open internet.

Expert
46

TLS / encryption strength

Whether your server still accepts outdated, insecure protocol versions that fail modern standards.

Expert
47

Mixed content

Insecure resources loading on otherwise-secure pages, weakening the padlock.

Expert
48

Advanced email security (MTA-STS, TLS-RPT)

The layer beyond SPF/DKIM/DMARC: enforcing encrypted mail delivery and reporting when it fails.

Expert
49

Performance & SEO (Google Lighthouse)

Full performance and SEO scoring with Core Web Vitals — how fast your site really is, and how well search engines can read it.

Expert

A human review

Every Expert report is read by a cybersecurity professional before it reaches you. They tell you which two findings actually matter this month, and which can wait. That judgement is the one thing no scanner can automate.

Expert

What we don't check

This section matters more than the list above. Any company can tell you what it does. Overclaiming is how this industry lost people's trust — so here are our limits, stated plainly.

  • This is not a penetration test. We don't attack your site, exploit anything, or attempt to break in. A real penetration test costs thousands and is a different exercise entirely. Anyone selling you one for a few hundred dollars is not selling you one.
  • We don't log in. We check what's publicly visible. We never authenticate into your site, admin panel or database — so vulnerabilities that only exist behind a login are outside what we can see.
  • We don't touch your customer data. We never read your database, your orders or your customer records. We don't want them and we don't have them.
  • We don't give legal advice. When something is a legal judgement — like whether your refund wording breaches the ACL — we flag it for professional review. We tell you what we found and why it's worth a lawyer's eye. We don't rule on it.
  • We can't always read a JavaScript-heavy site. Some sites build their content in the browser. When we can't reliably read yours, we say so and mark the scan as limited — rather than reporting things as "missing" when we simply couldn't see them.
  • We never scan without permission. Every scan requires you to confirm you own the site or are authorised to check it. We don't scan uninvited, and we will never email you out of the blue to say your website has problems.

That's the whole picture. If a check isn't on this list, we don't run it — and we won't imply we did.

See it applied

Now see what a real report looks like.

Read a full Expert report before you spend anything — or run a free Scorecard and find out how many of these checks your own site passes.