{"slug": "canopy-grade-any-website-s-health-in-4-seconds", "title": "Canopy: Grade any website's health in 4 seconds", "summary": "Canopy, a website health grading tool, launched a free service that grades any website in four seconds using twelve analyzers covering security headers, CSP, cookies, privacy, AI readiness, email, DNS, SEO, performance, accessibility, links, and PWA. The tool offers unlimited scans without an account, includes a CI gate, and provides letter grades with exact fixes, along with monitoring tools like uptime checks every 15 minutes and weekly digests.", "body_md": "# Grade any website in *four seconds.*\n\nTwelve analyzers: security headers, CSP, cookies, privacy & trackers, AI readiness, email, DNS, SEO, performance, accessibility, links & PWA. Each returns a letter and the exact fix.\n\n- Free, no account\n- Unlimited scans\n- CI gate included\n- Grades its own site\n\nTry: [this site](/?url=https%3A%2F%2Fcanopystack.dev) ·\n[github.com](/?url=https%3A%2F%2Fgithub.com) ·\n[example.com](/?url=https%3A%2F%2Fexample.com)\n\n## Live examples — real grades, updated hourly\n\n[github.com full report →](/site?domain=github.com)\n\n[wikipedia.org full report →](/site?domain=wikipedia.org)\n\n[stripe.com full report →](/site?domain=stripe.com)\n\n[nytimes.com full report →](/site?domain=nytimes.com)\n\n## Scan & monitor 7 tools\n\n### Whole-site scan\n\n11 layers at once, one combined grade.\n\n### Multi-page sweep\n\nYour sitemap's pages checked together: drift shows up per page.\n\n### Dashboard\n\nAll your domains as a live wall of grade badges on one URL.\n\n### Uptime\n\nPinged every 15 minutes, public status pages, 7 days of history.\n\n### Trends\n\nEvery monitored grade over time, in one view.\n\n### Weekly digest\n\nWhat changed across your sites this week, regressions first.\n\n### Compare\n\nTwo URLs side by side on any layer, drift highlighted.\n\n## Twelve graded layers\n\n### Security headers\n\nHSTS, framing, sniffing, CORS, mixed content: 15 checks.\n\n### CSP deep-dive\n\nReads your policy the way an attacker would.\n\n### Cookie security\n\nEvery Set-Cookie, inspected like a browser does.\n\n### Privacy & trackers\n\nWhich analytics, ad pixels & recorders watch your visitors, and do you ask consent?\n\n### Email security\n\nSPF, DMARC, DKIM: can strangers send mail as you?\n\n### DNS posture\n\nDNSSEC, CAA, redundancy, IPv6.\n\n### SEO & meta\n\nTitles, descriptions, canonicals, OG, sitemap.\n\n### Performance\n\nTTFB, blocking scripts, layout shift, third-party fan-out.\n\n### Accessibility\n\nAlt text, labels, zoom, heading order: WCAG smoke test.\n\n### Link health\n\nDead links, stale redirects, insecure targets, probed live.\n\n### AI readiness\n\nDoes your site say whether AI crawlers may read it?\n\n### PWA & installability\n\nManifest, icons, display mode: can it be installed as an app?\n\n## Fix & automate 17 tools\n\n### Fix pack\n\nA config for your server containing only the fixes you need.\n\n### Reference configs\n\nThe full A-grade setup for six stacks, copy-ready.\n\n### CI gate\n\ncurl with fail_under=B blocks deploys that regress.\n\n### Badges & snapshots\n\nLive grade badges for READMEs; 90-day frozen report links.\n\n### Redirect tracer\n\nFollow a URL hop by hop: loops, downgrades, wasted hops.\n\n### Exposed files\n\nIs your .git, .env, a DB dump or phpinfo() reachable? Content-verified, no false alarms.\n\n### security.txt\n\nCheck or generate your RFC 9116 vulnerability-disclosure policy, expiry and all.\n\n### robots.txt\n\nValid, or secretly an HTML page, or one stray Disallow: / from deindexing you? Read as a document.\n\n### Sitemap audit\n\nIs your sitemap.xml valid XML, within Google's 50k-URL cap, and full of absolute HTTPS URLs, or secretly an HTML 404?\n\n### Social preview\n\nSee how a link unfurls on X, Facebook, Slack, before you post.\n\n### SERP preview\n\nSee your title and description as a Google result — with the real pixel width that decides whether your title survives or gets cut with an ellipsis.\n\n### Schema generator\n\nGenerate paste-ready JSON-LD for review stars, FAQ, breadcrumbs, or paste your own and check it wins the rich result, against Google's rules.\n\n### CSP builder\n\nBuild a hardened Content-Security-Policy from what your site loads (Analytics, Fonts, Stripe, YouTube), starting from default-src 'self'. The author-side mirror of the CSP layer.\n\n### Email records\n\nGenerate correct SPF & DMARC records from who sends your mail (Google, Microsoft 365, SendGrid, SES), or lock down a domain that sends none. The author-side mirror of the email layer.\n\n### robots.txt builder\n\nGenerate a valid robots.txt: keep admin & cart paths private, declare your sitemap, and opt out of AI training while staying citable in ChatGPT & Perplexity answers. The author-side mirror of the robots.txt and AI layers.\n\n### SRI hashes\n\nGenerate Subresource Integrity hashes for the CDN scripts and styles you embed, so the browser refuses a file a hijacked CDN has swapped — plus the CORS check that stops SRI silently breaking the load.\n\n### Pro (waitlist)\n\nAlerts on regressions, private slots, higher limits.\n\n## What the header scan checks 15 checks\n\nHTTPS enforcement (HTTP → HTTPS redirect) · Strict-Transport-Security · Content-Security-Policy · X-Content-Type-Options · clickjacking protection (X-Frame-Options / frame-ancestors) · Referrer-Policy · Permissions-Policy · Cross-Origin-Opener-Policy · cookie security (Secure / HttpOnly / SameSite) · CORS (Access-Control-Allow-Origin reflection & credentials) · mixed content (http:// scripts, styles, frames & images on HTTPS pages) · Subresource Integrity on third-party scripts/styles · cache-control sanity · security.txt (RFC 9116) · information disclosure (Server / X-Powered-By). Each rolls up to a letter grade with the exact fix to apply.", "url": "https://wpnews.pro/news/canopy-grade-any-website-s-health-in-4-seconds", "canonical_source": "https://canopystack.dev/", "published_at": "2026-08-11 00:15:45+00:00", "updated_at": "2026-08-11 00:40:34.976496+00:00", "lang": "en", "topics": ["ai-tools", "developer-tools"], "entities": ["Canopy", "GitHub", "Wikipedia", "Stripe", "The New York Times"], "alternates": {"html": "https://wpnews.pro/news/canopy-grade-any-website-s-health-in-4-seconds", "markdown": "https://wpnews.pro/news/canopy-grade-any-website-s-health-in-4-seconds.md", "text": "https://wpnews.pro/news/canopy-grade-any-website-s-health-in-4-seconds.txt", "jsonld": "https://wpnews.pro/news/canopy-grade-any-website-s-health-in-4-seconds.jsonld"}}