Back to selected work

NovaraCode tool / public website analysis

Website Inspector

A free bilingual website analysis tool that turns public performance, security, HTTPS, technical SEO, AI visibility, email, and WordPress signals into an understandable report.Open Website Inspector

Our responsibility

Product architecture, deterministic checks and scoring, isolated scanner infrastructure, full-stack implementation, bilingual report UX, caching, realtime progress, and operational safeguards.

A broad technical baseline in one scan

Website Inspector examines DNS, HTTP and redirects, TLS certificates, security headers, cookies, metadata, technical SEO, AI crawler visibility, email DNS, passive WordPress signals, and page delivery. An optional Google PageSpeed mobile test adds rendered performance, accessibility, best practices, SEO, and browser-workload measurements when available.

Progressive reports written for real decisions

Each module reports progress independently through realtime updates with polling fallback, so one unavailable check does not discard the rest of the scan. Results separate passes, warnings, serious issues, limited observations, and unavailable checks, then pair plain-language context with confidence, technical evidence, likely impact, and practical remediation.

Untrusted scanning behind a strict boundary

User-submitted domains are processed by an isolated, non-root scanner with its own authenticated Redis broker, constrained resources, bounded requests, and no application or database credentials. Public-address validation covers IPv4 and IPv6, connections are pinned to approved DNS results, every redirect is revalidated, and host firewall rules prevent the scanner from reaching NovaraCode infrastructure or private networks.

Built as an extensible production service

Laravel remains the authoritative coordinator for scan state, findings, scoring, caching, rate limits, duplicate suppression, retention, shareable snapshots, rescans, and comparisons. Checks use versioned deterministic rules rather than AI-generated judgments, while feature flags, queue limits, module timeouts, and a global kill switch keep the main website and contact systems available under load.

From submitted domain to actionable report

Every target passes through validation and a bounded module pipeline before deterministic findings are assembled into a clear report.

  1. Submit a public domain

  2. Resolve and validate destinations

  3. Run bounded technical checks

  4. Explain and prioritize findings

Technologies and capabilities

Next.jsReactTypeScriptLaravelPHPRedis StreamsLaravel ReverbMySQLDockerDNSTLSPageSpeed Insights

Related services