
Siteory
A production-grade website audit that checks SEO, AI search visibility, technical setup and security, then turns every finding into a prioritized, developer-ready fix.
Timeline
2026 - Present
Role
Full Stack Developer
Team
Solo
Status
CompletedTechnology Stack
Key Challenges
- Keeping security results honest: confirmed findings are kept apart from observations
- Starting expensive paid crawls only after the server confirms payment
- Bounded crawls that honor robots.txt and say exactly what was not checked
Key Learnings
- Scores should never invent data: what is not measured shows Unavailable, not 0
- An audit is only useful if the fix reaches the person who ships it
- AEO is about what answer engines can actually read on the page
Overview
Siteory is a website audit for the way people search today. Paste a URL and it crawls the site, checks SEO, AI search visibility (AEO / GEO), technical setup and security, then ranks everything it finds into one prioritized fix list. Every result explains why it matters, what to change and how to fix it, and comes with a prompt you can paste straight into a coding agent.
It reads public HTML, so it works on any stack: WordPress, Shopify, Webflow, Framer, Wix, Squarespace, Ghost or Next.js.

Features
- Four areas, one report: SEO, AEO, AI visibility and security each get their own score and findings, ranked together in one fix list.
- Evidence, not just a score: each result shows what was requested, what came back, why it matters and what to change.
- Findings vs observations: an issue Siteory classified as real lowers the score; something only observed, like a port visible from the internet, is informational and never presented as a vulnerability. Clean checks are reported as verified negatives.
- Developer-ready fix prompts: every finding ships with a prompt for Claude, Codex, Cursor or OpenCode. You review the change, ship it, then re-scan to confirm.
- Reports you can forward: an executive summary, prioritized fixes, per-area detail and crawl coverage, plus Markdown exports (
summary.md,prioritized-fixes.md,seo.md,aeo.md,security.md) on paid audits. - Honest coverage: the report shows how many URLs were discovered and analyzed, and why the crawl stopped.
Why I built this
SEO tools and security scanners both stop short of the next commit. I wanted one crawl that says what is wrong, shows the evidence, and hands the fix to whoever has to ship it.
Most tools look at one layer. A site can look fine while missing canonicals, an llms.txt file or a Content-Security-Policy sit underneath. Siteory looks at all of them in one pass and ends with something a developer can act on.
How it works
- Enter your website: a URL you own or have permission to test.
- Siteory discovers the site: a same-host crawl that honors
robots.txt. - Siteory analyzes and classifies: SEO and AEO on every scan, plus security on paid audits.
- Get the prioritized report: scores, ranked fixes, evidence, coverage and a prompt for each finding.

Technical Stuff
Platform
- Next.js: the product and marketing site, served through Cloudflare.
- Google or email sign-in: anonymous visitors get a quick preview; full audits run on a verified account.
Audit pipeline
- Crawler: requests public pages as
SiteoryBot/1.0, honorsrobots.txtrules forUser-agent: *, and works inside fixed limits (about 8 pages at depth 2 for a preview, 25 pages at depth 3 for a paid audit). - SEO analyzer: titles, meta descriptions and headings, canonicals and canonical chains, robots and sitemap coverage, broken links, orphan pages, duplicate titles and crawl depth.
- AEO analyzer: thin copy, identity signals, JSON-LD types and discoverability, plus a dedicated
llms.txtandllms-full.txtpass on paid audits. - Security: deterministic checks on response headers, CSP strength and auth cookie flags, application analysis through Hermes, and external exposure data from Shodan InternetDB. Evidence is correlated, then each result is classified as a finding or an observation.
Data, payments and email
- Redis: holds scan state. Anonymous previews expire in about an hour; signed-in scans live for about seven days and can be archived to the account.
- Dodo Payments: credits are granted only on a confirmed
payment.succeededevent, and the paid scan is keyed by payment id so a webhook replay never starts a second crawl. If a full audit fails, the credit is returned automatically. - Resend: emails the account holder once when a paid report is ready.
Scoring
SEO, AEO and security each start at 100. Confirmed findings subtract a fixed penalty by severity; observations subtract nothing. Search visibility, GEO ranking and authority are shown as Unavailable unless a licensed data provider is configured, never as 0.

Technical Challenges & Solutions
Challenge 1: Security results people can trust
- Problem: external exposure data, like an open port, is not automatically a vulnerability, but most scanners present it as one.
- Solution: every result is labeled as a finding, an observation or a verified negative. Only findings carry a severity and change the score.
Challenge 2: Paid crawls that never run twice
- Problem: a full audit is expensive, and checkout redirects or replayed webhooks must not start extra crawls.
- Solution: credits are added only when the server confirms payment, the paid scan is keyed by payment id, and a failed audit returns its credit.
Challenge 3: Telling users what was not checked
- Problem: audits are bounded, and silence about skipped pages reads as "everything is fine".
- Solution: paid reports include crawl coverage: URLs discovered, pages analyzed, remaining URLs and the reason the crawler stopped.
Pricing
- Free: a quick SEO and AI-visibility preview without an account, then one full audit with a verified account.
- Single: $9 for one full paid audit.
- Pro: $49 per month for ten full audits.