SEO Scanner Documentation
SEO Scanner is a technical SEO platform for full-site crawling, technical checks, content analysis, schema validation, broken-link detection, WHOIS lookups, and export-ready reports. This documentation covers the product, account-based API access, and the downloadable files you can use in your workflow.
What SEO Scanner Covers
SEO Scanner is designed for technical audits, content quality reviews, and operational reporting. It focuses on the parts of SEO that teams need to diagnose quickly: crawlability, on-page markup, duplication, structured data, images, content quality, security, and broken links. Public API access is available for page analysis, WHOIS/RDAP lookup, sitemap discovery, domain snapshots, badges, OG images, report retrieval, and browser vitals.
Scan Modes
Single Page Analysis
Use this mode when you need a focused audit for one URL. It returns core SEO checks, content analysis, schema validation, link metrics, image diagnostics, security headers, and export-ready page data.
- Fast page-level diagnosis
- Ideal for QA, templates, and landing pages
- No deep crawling required
Full Website Crawl
SEO Scanner looks for a sitemap first. If none is found, it falls back to deep crawling to discover indexable URLs. This mode powers site-wide issue summaries, duplicate detection, internal-link insights, and richer exports.
- Sitemap discovery + fallback deep crawl
- Issue aggregation across all pages
- Built for site audits and client deliverables
Technical SEO Coverage
Technical checks are the core of the scanner. Every analyzed page is inspected for title length, meta description quality, heading structure, canonical usage, robots/indexability signals, Open Graph, Twitter Cards, hreflang, structured data, image hygiene, redirects, HTTP status, and security headers.
- Title, meta description, H1/H2/H3 consistency
- Canonical and robots checks
- Open Graph, Twitter, hreflang, and JSON-LD detection
- Image alt text, dimensions, and lazy-loading signals
- Redirect chains, HTML size, load time, and HTTP status checks
- Security headers: HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and more
Structured Data Validation
The schema panel validates JSON-LD blocks, detects rich-result candidates, surfaces missing properties, and shows raw markup for debugging.
Organization WebSite SoftwareApplication FAQPage BreadcrumbList WebApplicationContent Analysis
SEO Scanner also evaluates content quality signals. This is separate from PageSpeed and focuses on what helps content teams and SEO specialists improve clarity, relevance, and crawlable on-page depth.
Readability
Sentence length, readability score, and content difficulty classification.
Density Signals
Top keywords, bigrams, trigrams, and keyword stuffing detection.
Content Depth
Word count (CJK-aware), sentence count, paragraph count, and text/HTML ratio measured against markup with CSS and JavaScript excluded.
Links, Security, and Reporting
Links & Broken Links
Inspect internal vs external links, nofollow usage, empty anchors, and broken-link results. The links tab is useful for auditing navigation, orphan-risk patterns, and content hubs.
Exports & Delivery
Generate PDF, CSV, JSON, or HTML output. PDF reports are designed for agency-ready executive summaries plus per-page technical detail. Email sending is also supported directly from the app.
API Reference
The API requires a logged-in account with API access enabled in settings. Use your authenticated session when calling these endpoints. It exposes page analysis, WHOIS/RDAP lookup, sitemap discovery, domain snapshots, badges, OG images, public report retrieval and browser vitals. PageSpeed is intentionally excluded from the API. The /api/v1 endpoints are rate limited to 30 requests per minute per IP.
Tip: the API is session-based, so curl clients must send the logged-in cookie from your browser session.
Base URL
POST /analyze
Analyze a single page and return technical SEO, schema, content, image, link, and security data.
POST /whois
Fetch RDAP / WHOIS data for a domain or URL.
POST /sitemap
Discover and parse the sitemap for a website, including common fallback locations.
GET /api/site/:domain
Return the latest public snapshot and history for a domain.
GET /api/badge/:slug
Return the embeddable score badge for a public report.
GET /api/og/:slug
Return the Open Graph image for a public report.
GET /api/report/:slug
Return the stored JSON analysis for a public report. Private reports are served only to their owner session and stay out of the sitemap.
GET /translations/:lang.json
Public, read-only dictionary that powers the report interface for in-place language switching. No authentication required.
POST /api/vitals
Send Core Web Vitals from the browser for aggregation.
Downloadable Files
Use these files to integrate the API into internal tools, collections, onboarding docs, or client handoff packages.
OpenAPI JSON
Machine-readable API definition for SDKs, tooling, and import workflows.
/docs-files/openapi.json
OpenAPI YAML
Human-friendly OpenAPI version for editing and documentation generators.
/docs-files/openapi.yaml
Postman Collection
Ready-to-import requests for the account-based API endpoints and browser vitals.
/docs-files/seoscanner-postman-collection.json
Quickstart Markdown
Shareable technical onboarding doc for teams and clients.
/docs-files/quickstart.md
Errors and Limits
Every endpoint returns JSON. Validation problems return HTTP 400 with a machine-readable error message, authentication problems return 401, and exceeding the rate limit on /api/v1 endpoints returns 429 with a retryAfter field in the JSON body plus X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers. URLs that resolve to private or non-public network addresses are not fetched. Responses from upstream sites vary: a page that returns HTTP 200 with an interstitial or bot challenge is analyzed as-is, and the report shows the detected status instead of the intended page.
The analyzer measures what a crawler sees in the fetched HTML. Content rendered only by client-side JavaScript is not part of the fetched document, so pages that depend heavily on scripts should be validated with the rendered-DOM tools of your choice. Real PageSpeed scores come from Google's PageSpeed Insights API when enabled; lab scores describe the tested URL at test time and do not replace field data from the Chrome User Experience Report.
Reports you keep private stay out of the sitemap and are served with noindex. Publishing a report creates a permanent public URL for the exact scan you saved: re-running a scan creates a new report instead of changing the published one, so shared links remain stable.
FAQ
Does the API include PageSpeed?
No. The product UI supports PageSpeed analysis, but the API is intentionally limited to technical SEO analysis, WHOIS/RDAP, sitemap discovery, snapshots, badges, OG images and vitals.
Can I use SEO Scanner for client reporting?
Yes. The PDF export is designed for professional delivery, while CSV, JSON, and HTML exports support internal analysis and automation.
Do I need an API key?
No API key, but you need a free account. Enable API access in your account settings and use your session cookie.
What is rate limited?
The /api/v1 endpoints are limited to 30 requests per minute per IP address. Every response includes X-RateLimit-* headers; a 429 body also carries a retryAfter value in seconds.
Can SEO Scanner submit my URLs to Google?
Sitemaps and Search Console cover normal pages. Google's Indexing API accepts only JobPosting or BroadcastEvent-in-VideoObject pages; for those, the Indexing tab sends notifications through your connected Google account. An accepted notification confirms delivery only — verify index status in Search Console.