Documentation

AI visibility, security audits, deploy monitoring, fix packs, and portfolio rollups — one guide for the full platform

New to the topic? Browse our resources & guides or read the detect → fix → deploy → verify workflow.

Getting Started

1. Create Your Account

Sign up for a free account to start auditing your websites. No credit card required for preview scans.

2. Add Your First Site

From your dashboard, click "Add Site" and enter your website URL. Uptime monitoring begins immediately and your first security audit is queued automatically — no extra step required.

3. Set Up AI Visibility

After adding a site, pick prompts from the library or use query fan-out. Scheduled visibility checks run on your plan cadence and alert you when mention or citation rates drop.

4. Review Findings & Export Fix Packs

Open any audit or AEO finding and use Fix Pack Export to copy instructions formatted for Cursor, Lovable, a GitHub Issue, or a PR description. Link a GitHub repo in site settings for one-click issue creation.

5. Hook Deploy Webhooks & Verify Fixes

On each site's detail page, generate a deploy webhook secret and POST from your CI/CD pipeline after shipping. AppScan captures what changed, runs verification checks, and updates the Fix & Verify Timeline so you can prove scores improved.

6. Read Reports & Portfolio Rollup

Weekly and monthly reports combine security findings with uptime and AI visibility context. Use the Portfolio view to see health, SSL risk, open issues, and visibility drops across every site in your org.

Audit Tiers

Free Preview Scan

Quick security and AI readiness check for your homepage

  • Homepage-only scan
  • Security headers analysis
  • AI readiness score
  • Overall health score

Starter Audit

Comprehensive audit with SSL analysis and multi-page discovery

  • Everything in Free Preview, plus:
  • Deep SSL/TLS analysis (A+ rating)
  • Mobile + desktop performance analysis
  • SEO, Accessibility, Best Practices scores
  • Real user performance metrics
  • Key pages analyzed via sitemap when available
  • Detailed findings with recommendations

Pro Audit

Multi-page crawl with advanced analysis

  • Everything in Starter, plus:
  • Intelligent crawling (up to 20 pages via sitemap)
  • Desktop + mobile screenshots
  • Full accessibility audit (90+ checks)
  • Structured data detection (Schema.org)
  • Image optimization analysis

Enterprise Audit

Full site crawl with deep analysis and priority support

  • Everything in Pro, plus:
  • Extended crawling (20+ pages via sitemap)
  • Runtime health monitoring
  • Console error detection
  • Priority support
  • Custom reporting

Understanding Your Report

Scores Explained

Security Score

Security rating based on security headers, vulnerability detection, and exposed secrets. This is separate from the SSL/TLS score.

SSL/TLS Score

Dedicated score and grade (e.g. A+): certificate validity, protocols, forward secrecy, and known vulnerabilities. Shown separately from the overall Security score.

Performance Score

Performance (Core Web Vitals, load time). Scores typically range from about 20–80 because we measure mobile under simulated throttling—stricter than other categories. Our gauge treats 75+ as Great, 50–74 Good, 25–49 Low, and below 25 Bad.

Overall Health Score

Combined score across all dimensions: Security (25%), UX (20%), Runtime Health (15%), Performance (10%), SSL (10%), AI Readiness (10%), SEO (10%). This represents your site's complete health.

SEO Score

Search engine optimization rating including meta tags, structured data, mobile-friendliness, and crawlability. For Answer Engine Optimization (AEO) and AI search readiness, see our dedicated AEO page.

UX Score

User experience score based on accessibility plus our own checks (viewport meta, automated accessibility checks). Shown separately from the raw Accessibility and Best Practices scores below.

Accessibility Score

Accessibility score: WCAG compliance, 90+ checks including color contrast, ARIA labels, keyboard navigation, and screen reader compatibility.

Best Practices Score

Best practices: HTTPS usage, console errors, vulnerable JavaScript libraries, and modern web standards. Shown separately from Security and UX.

Finding Severity Levels

Critical

Severe security vulnerabilities or major issues that require immediate attention. These can lead to data breaches, site compromise, or significant user impact.

High

Important issues that should be addressed soon. May impact security, performance, or user experience significantly.

Medium

Issues that should be fixed but don't pose immediate risk. Often related to best practices, optimization, or minor security concerns.

Low

Minor improvements or recommendations. Nice to have but not urgent.

Info

Informational notices or suggestions for enhancement.

Advanced Features

Real User Metrics

Actual performance metrics from real users visiting your site over the past 28 days. This includes Core Web Vitals and overall performance category (FAST/AVERAGE/SLOW).

Note: Only available for sites with sufficient traffic. New or low-traffic sites may not have real user data.

Structured Data Detection

We automatically detect Schema.org markup (JSON-LD and Microdata) on your site. Structured data helps search engines understand your content and can enable rich snippets in search results.

Common schemas: Organization, Article, Product, LocalBusiness, FAQ, BreadcrumbList, and more.

Image Optimization Analysis

Premium audits analyze all images on your homepage for:

  • • Missing alt attributes (hurts SEO and accessibility)
  • • Oversized images (serving higher resolution than needed)
  • • Legacy formats (JPEG/PNG vs modern WebP/AVIF)
  • • Responsive image usage (srcset attributes)

Intelligent Crawling

Premium audits automatically discover and scan up to 20 pages from your site using sitemap.xml and robots.txt. We prioritize important pages and respect crawl directives.

Best Practices

Enable Weekly Automatic Audits

On each site's detail page, keep "Weekly automatic audits" enabled (default). AppScan queues a security audit every 7 days within your plan's monthly limit — staggered so audits don't pile up on one day.

Use Fix Packs, Not Ad-Hoc Notes

Export Fix Packs from audit and AEO findings instead of copying raw text. Formats are tailored for your dev workflow and include enough context for AI coding tools or GitHub tickets.

Verify After Every Deploy

POST to your site's deploy webhook from CI/CD after shipping, or click Record Deploy manually. Track progress on the Fix & Verify Timeline and confirm verification audits show improved scores.

Prioritize Critical & High Findings

Focus on critical and high severity issues first. These have the biggest impact on security and user experience.

Review Weekly Reports

Enable weekly summary emails in Report Settings. Reports include security findings plus uptime and AI visibility context — useful even when no new audits completed in the period.

Monitor Trends

Track your scores over time to see improvements and catch regressions. Your dashboard shows historical audit data.

Need Help?

Have questions or need assistance? We're here to help!

Use the contact form at /contact