We audit your website, fix it, or build it correctly from the ground up.
WebTrustEngine measures security, accessibility, performance, SEO, structured data, privacy and AI visibility. It delivers a leadership-ready report, actionable fixes and a verified website through one evidence chain.
What this means for you: every finding arrives with file-level evidence — leadership reads the report, your technical team verifies the annexes.
- I have a website but do not know its conditionWebsite Audit and Executive ReportWe examine your URL or site package and deliver the risks, affected pages and business priorities as a clear executive brief, detailed technical annex and prioritized action plan.Request a website audit →
- I have a website and want its problems fixedExisting Website ImprovementWe prioritize the audit findings, complete the applicable fixes on a safe working copy, rescan the website and prove the before-and-after result.Improve my existing site →
- I need a new websiteNew Website Design and DevelopmentWe design and develop a fast, accessible and secure website aligned with your brand and business goals, prepare it for SEO and AI visibility, and verify the delivery with the engine.Plan my new website →
See what the audit produces: a sample executive report from a real run →
WHY GOVERNANCE?
The web is no longer a one-off project
A website is now a human storefront plus a machine surface.
The page a visitor sees is simultaneously the input of dozens of automated readers. A page flawless for humans can carry missing headers, broken schemas and unclear identity signals for machines.
Even with great design, machine readability can be weak. Visual redesign projects rarely touch the meta layer, security headers or structured data; the site looks new while its audit surface stays old.
WHO USES IT
Who uses it, and when?
Four typical moments: an evidence-based snapshot before a corporate site renewal; independent acceptance of an agency delivery; a recurring governance round; and quick due diligence before a merger or transfer.
WHAT IS R50?
Every published figure — counted from code
R50 is WebTrustEngine's public capability set. Its distinguishing trait is number discipline: every published figure is counted from code; different units are never merged into one total.
Claim safety
Every published claim is tied to code and an evidence file; no figure is written by hand — source-level gates enforce it.
FOUR MODES
Review → SafeFix → Build → Deploy-Verify
Each mode produces its own evidence; no mode issues a live pass.
Review
An evidenced baseline without touching a file: 10-domain score plus classified findings.
score + findingsSafeFix
Low-risk fixes in a working copy; every change is written to a manifest.
fix manifestreversibleBuild
A schema-ready static surface: meta, canonical, hreflang, JSON-LD, accessibility skeleton.
static surfacereversibleDeploy-Verify
Post-upload live header pulls and independent-tool recipes; producing files is not enough.
live proof
The 10-domain score model
Each domain with its one-line scope; evidence, sample findings and boundaries live on the Score Model page.
Security Headers
HSTS · CSP · nosniff
TLS / HTTPS
encrypted transport
Technical SEO
meta · canonical · sitemap
Structured Data
JSON-LD identity
Accessibility
alt · label · heading
Performance
static readiness
AI / GEO / AEO
readability
Cookies
tracker visibility
Code Security
secrets · exposure · patterns
Delivery
deployment hygiene
SAFEFIX
Not a rebuild — a safe improvement

The evidence package: files, not a score
A changed-files list, a rollback manifest and a before/after score ship together. Every change reverts in a single step.
See the processchanged_filesFlat list of every touched path.
fix_manifestPer-file before/after hashes.
rollback_manifestThe single-step way back.
DEPLOY-VERIFY
Producing files is not enough
Upload, cache purge, live header pulls and independent-tool recipes: evidence completes in production.

- Live header pull
- robots/sitemap live
- OG card refresh
- Search Console submit
- SSL Labs run
SECURITY BOUNDARY
Not a pentest — and it says so
In short: the engine sends no requests to your site; it looks for security signals in your files and never attempts an attack. This boundary is deliberate and stated in writing.
A static security review is security analysis over source, configuration and output files without touching the target system. WebTrustEngine's security layer stays within this definition and has four blocks: secret scan (key/password/token leakage), exposed files (.env, backups, .git, config exposure), client-side risky patterns (eval, document.write, dangerous sinks) and server-side SAST classifications (SQLi/command/traversal/deserialization/SSRF/XXE markers).
SCA/CVE logic accompanies these: risky ranges of known library versions are flagged; but no 'this version is exploitable' claim is made — the flag binds to an update recipe. CSP/HSTS readiness and OWASP mapping put findings into a shared language.
When is it not a pentest? Always — in this product. No active payloads, no live port scans, no authentication-bypass attempts, no exploit generation. Any DAST-class behaviour requires written authorization, ownership verification and a separate scope document. This legal and ethical boundary is not a weakness; it is trust discipline: the client knows exactly what they bought and what must be ordered separately.
Boundary glossary — what does static scanning cover?
- secret scan
- exposed files
- JS sink patterns
- SCA/CVE flags
- CSP/HSTS readiness
- OWASP mapping
- DAST = authorization + scope
Boundary
Active testing requires written authorisation; the engine offers static security review.
Clear boundaries make starting easy: get an evidenced snapshot without a single file being touched.
Prepare an audit requestVISUAL SYSTEM
The brand speaks its own visual language

Critical questions — quick answers
Q: How do we start?
A: You share your site address or a site package (ZIP); the first review produces an evidenced snapshot without changing a file. Scope and schedule are settled on that snapshot.
Q: What is delivered?
A: An executive brief plus a technical-annex report (DOCX/PDF) and a machine-readable evidence pack: changed files, manifest, checksums, rollback plan. Scanning and reporting are automated.
Every file in the evidence pack, explained in the Evidence Hub
Q: Why is there no price on the site?
A: Quotes follow scope: one site or a multilingual estate, with or without live verification. A fixed list price is therefore not published; the rule that every published figure must be provable applies to pricing too.
Q: What can it see without touching the live site?
A: All in-file signals in ZIP/local input: meta, schema, header readiness, accessibility markers, static security patterns.
Q: ZIP vs live-URL analysis?
A: ZIP shows file truth; live URL shows response truth; headers and redirects finalize only live.
Q: What if the site breaks after SafeFix?
A: The rollback manifest reverts in one step; the backup dir ships in the package.
Q: How is the rollback manifest used?
A: Copy files back from the backup dir; the changed/created lists guide you.
Q: Which changes are the owner's commercial call?
A: Meaning-changing content, brand/voice preferences and legal text are commercial decisions; the live publish decision also belongs to the owner.
Q: Why are the figures never summed?
A: Checks, patterns, bridges, fixers and recipes count different kinds of work; different units are never merged into one total. Inflating a headline figure is deliberately rejected.
Q: How is the 348 figure counted?
A: Counted from code by the CLI; the quality gate and the build ledger must agree with the same figure, so inflation is structurally impossible.
WHY WEBTRUSTENGINE?
Quick preview: against the four closest products
These four differentiators are what matter for an evidence-bound decision file. The full table is 12 products × 16 capabilities on a separate page; every competitor cell is bound to an official product page, with no unsourced green or red.
- URL, ZIP and local-folder input — no equivalent found on hosted crawlers.
- Hashes, manifests and number provenance — the same input yields the same number.
- Reversible fixes with a rollback manifest.
- Local, controlled data processing.
Ready for the first review?
Get an evidenced baseline without touching a file; scope and quotes are settled via contact — pricing is not published on this site. Until a verified direct channel is published, requests travel through the topic lanes on the contact page as a scoping exchange.






