Docs
How Scaneryx works
Scaneryx is an automated QA tool for websites built with Lovable, Bolt, Replit, Cursor or Claude Code. It loads your site in a real browser and reports what is broken — with evidence and a copy-ready fix prompt.
How a scan works
- You submit a public URL. The server validates it, resolves DNS and rejects private or reserved addresses.
- The scan is queued in the database. Quotas are enforced there: one scan at a time, monthly limit per plan.
- The scanner (a separate Node.js service with Playwright + Chromium) claims the scan and opens the site.
- It monitors network and console, inspects the DOM, checks internal links, loads internal pages and repeats the layout check on a mobile viewport.
- Findings are scored, stored and streamed back to your browser in real time.
What is checked
- Network
- HTTP 4xx/5xx responses, failed requests and resources, requests to localhost/private addresses.
- Runtime
- console.error calls, uncaught exceptions and page errors.
- Navigation
- Broken internal links (HTTP ≥ 400 or unreachable) and routes that crash with 5xx.
- Images
- Images that fail to load and images without an alt attribute.
- SEO
- Missing or empty <title>, missing meta description, missing or multiple H1, missing viewport.
- Accessibility
- Inputs, textareas and selects without labels, buttons and links without accessible names, broken ARIA references, focusable content inside aria-hidden, disabled zoom, missing lang.
- Forms
- Structural analysis only: unlabeled fields, forms posting to plain HTTP. Forms are never submitted.
- Layout
- Horizontal overflow and elements outside the viewport on desktop (1440×900) and mobile (390×844), small tap targets.
- Performance
- Load duration per page, page weight and the number of failed resources.
Scoring
Scores use Score Engine 3.0. A scan starts at 100 and only verified findings deduct points — findings marked “likely”, “needs review” or “informational” are shown but never change the score. One root cause is one deduction, even when it appears on several pages (at most ×1.5).
Critical failure
−35
no cap
Major malfunction
−15
no cap
Limited usability
−10
max −30 in total
Accessibility
−8
max −20 in total
Performance
−8
max −15 in total
SEO
−3
max −8 in total
When a required check (start page, page structure, network, accessibility, mobile layout or performance) could not finish, the report says Score unavailable instead of showing 0 or 100. When only the crawl of subpages was cut short, the score covers the examined pages and says so.
AI Fix Prompt
Every report — on every plan, including Free — has a Copy AI Fix Prompt button per finding and one for all findings. The prompt is generated deterministically from the scan: what is broken, where, how Scaneryx proved it, what to investigate and how to verify the repair. It never invents source files or causes. Paste it into ChatGPT, Claude Code, Gemini, Cursor, Lovable, Bolt or Replit, deploy, and scan again.
Limits
- Up to 10 pages loaded in the browser and 30 internal links checked per scan.
- 30s timeout per page, 2 minutes per scan, at most 5 redirects.
| Plan | Scans / month | At the same time | Projects |
|---|---|---|---|
| Free | 3 | 1 | 1 |
| Starter | 15 | 1 | 3 |
| Pro | 30 | 2 | 10 |
| Growth | 60 | 3 | 25 |
| Power | 100 | 4 | 50 |
| Lifetime | Unlimited* | 4 | Unlimited |
* Lifetime: no monthly credit limit. Fair use applies — up to 50 scans per day and 4 at a time; no mass crawling or automated scanning of large domain lists.
Scanner & safety
Only scan websites you own or have permission to test. Scaneryx is a QA tool, not a security scanner. It identifies itself with a Scaneryx/0.1 user agent.
- Read-only: it never submits forms, logs in, signs up, buys anything or follows logout, delete, checkout or unsubscribe links.
- No port scanning, password guessing, exploit attempts or hidden admin discovery.
- It cannot reach localhost, private networks (10/8, 172.16/12, 192.168/16), link-local addresses, cloud metadata endpoints or internal hostnames — every connection, including redirects, is validated at connect time.
Partial results
Every scan has a time budget. Very slow or heavy sites (endless video streams, hundreds of requests) do not make the scan fail: Scaneryx stops the remaining checks in time and shows a partial report with exactly which checks ran, which were cut short and why. Load times are only reported when the browser measured them; links that answer 401/403/429 (login, bot protection, rate limits) are marked as unverifiable, not as broken.
Scans that fail because of Scaneryx itself (scanner crash, repeated interruptions) are not counted against your plan. Scans of sites that cannot be reached (wrong domain, server down) are counted.
AI AutoFix
With a connected GitHub repository, “Fix with AI” lets an AI read the scan evidence and your code, make the smallest change it can justify, and open a pull request on a new branch. Scaneryx never pushes to your default branch, never merges and never deploys.
- Scaneryx does not run your repository's code on its servers. Tests run in your own CI after the branch is pushed.
- Results: Verified fixed (CI passed and a re-scan of the preview deployment no longer finds the problem), Code change created (not fully verified), Fix failed or Manual review required.
- CI config, env files, lockfiles, package.json and deployment config are never changed.
- Included AI fixes per month: Pro 3, Growth 10, Power 20, Lifetime 5 (fair use). A fix that cannot start because Scaneryx cannot reach your repository or the AI service is refunded.