Skip to content
SiteList

qsa.sh Review: Strong utility with bottlenecks (78.6/100) — SiteList

qsa.sh earns a 78.6/100, distinguishing itself through an exceptional terminal-first usability and performance profile for security engineers. However, its market growth is currently limited by a critical lack of middle-of-funnel content and technical configuration oversights.

Reviewed by SiteList Engine · crawled August 3, 2026 · 34 dimensions · published

Quick facts

Metric Value
Domain qsa.sh
Category Cybersecurity (External Attack Surface Management)
Pricing SaaS (Freemium + Pay-per-scan)
Pages Crawled 10
Crawl Date 2026-08-03
Evidence
Pages Crawled
10
Crawl Date
2026-08-03

Executive summary

The technical and on-page foundation of qsa.sh is exceptionally strong (composite score 82/100, band 'good'), characterized by clean HTML, fast performance, and an intuitive terminal-first product model. However, growth is bottlenecked by configuration oversights—such as noindexing the contact page and disabling browser caching—alongside a visible content gap in research-stage and comparison keywords. Addressing these quick wins and building entity trust will enable substantial search visibility.

Top Themes

  • Technical Foundation & Caching Deficiencies: Aggressive no-store cache headers and noindexing on the contact page limit origin scaling and high-intent conversions.
  • Topical & Keyword Gap: Strong transactional intent capture is undermined by a complete lack of middle-of-funnel comparison and educational glossary content.
  • Entity Trust & AEO Readiness: The brand lacks explicit sameAs entity links, an llms.txt file, and open-graph completeness, hindering AI extraction.
  • On-Page Optimization & Schema Polish: Core pages miss rich result opportunities due to omitted Product and FAQ structured data.
  • Accessibility & Usability Friction: Minor contrast issues on muted text and focus indicator suppression create barriers for compliance.
Evidence
Overall Score
78.6/100

01 · First impressions & positioning — 30-second terminal scan with zero data retention

qsa.sh provides an immediate, friction-free security scan for developers by reversing the industry trend of black box tools. The site passes the five-second test by explicitly naming its open-source components like nmap and nuclei while committing to a zero-retention model. Its positioning is highly specific, targeting the active developer workflow rather than passive data collection. While it lacks traditional social proof, its transparency regarding tool versions serves as a credible proxy for trust. A minor naming inconsistency exists between the Tuxxin organization schema and the qsa.sh brand, which may cause slight friction during the payment process.

Evidence
Scan Time
~30 seconds
Tool Transparency
nuclei 3.3.9
Naming Consistency
Tuxxin vs qsa.sh

02 · Audience & messaging — curl-first CTA for high-sophistication security engineers

The site demonstrates a deep alignment with the security engineer's mental model by prioritizing functional utility over marketing fluff. By using curl as the primary call to action and providing detailed breakdowns of port-scanning logic, qsa.sh speaks directly to its technical audience. The messaging successfully addresses core anxieties regarding data retention and authorization, specifically through the empathetic 15-second window to press Ctrl-C safety feature. Navigation labels like Pricing and How it works are strictly functional. However, the pricing page introduces slight confusion by listing a tip option as coming soon while simultaneously offering a subscription tier.

Evidence
Primary CTA
curl qsa.sh
Consent UX
15-second window
Pricing Clarity
Tip option coming soon

03 · Usability — 10-second path from landing to terminal execution

Usability is exceptionally high due to a flat navigation structure and a nearly perfect information scent for its target demographic. A developer can identify the value proposition, view pricing, and execute a scan within seconds of landing. The Run it free button provides an immediate trial experience without the friction of account creation. Despite this efficiency, the mobile experience is hampered by a navigation stack that consumes significant vertical space, pushing the primary headline below the fold. Additionally, the unconventional no-account model, while technically superior for privacy, may require clearer FAQ guidance for users accustomed to traditional dashboards.

Evidence
Task Path
Home -> Pricing
Mobile Nav Friction
7 links above H1
Account Model
Opaque token

04 · Accessibility — 82/100 score marred by low-contrast muted text

The site features a strong technical foundation for accessibility, including functional skip links and proper semantic HTML5 landmarks. However, it fails WCAG 2.1 AA requirements for secondary information, where muted text colors lack sufficient contrast against the dark background. Interactive elements are also at risk due to the suppression of default focus outlines in the CSS, which can disorient keyboard-only users. Furthermore, the terminal simulation video lacks a text alternative or transcript, rendering the core product demonstration invisible to screen reader users. Addressing these contrast and focus-indicator issues is essential for full compliance.

Evidence
Contrast Ratio
< 4.5:1 on muted text
Focus Indicators
outline: none detected
Form Labels
1 missing label

05 · Design execution — 46 distinct spacing values indicate significant token drift

While the site achieves a high level of aesthetic alignment with its developer audience, the underlying design system suffers from inconsistent execution. Crawl data identified 46 distinct spacing values and 21 different font sizes, creating a subtle lack of visual rhythm across long-form pages. Mobile usability is particularly affected, with 14 tap targets on the homepage falling below the 44px minimum requirement. Additionally, the 13.6px font size used on buttons triggers browser zooming and accessibility flags on mobile devices. Standardizing these ad-hoc values into a consistent 8-step scale would significantly improve the site's professional polish.

Evidence
Spacing Tokens
46 distinct values
Mobile Tap Targets
14 below 44px
Button Font Size
13.6px

07 · Performance — 850ms LCP restricted by aggressive no-store caching

qsa.sh is a model of performance efficiency, achieving an 850ms Largest Contentful Paint by avoiding heavy images and custom web fonts. The site maintains a perfect 0.00 CLS score. However, the current configuration uses cache-control: no-store headers, which prevents browsers and CDNs from caching static marketing content. This forces a full origin request for every visit, resulting in a TTFB of 180ms—higher than expected for a Cloudflare-backed site. Moving third-party scripts from tuxxin.com to an asynchronous loading model and enabling edge caching would make the site feel instantaneous globally.

Evidence
LCP
850ms
Cache Header
no-store

09 · Writing quality — 92/100 for transparent, expert-level technical copy

The writing quality is exceptional, characterized by high specificity and the total absence of SaaS clich s. The site builds authority by citing exact tool versions, such as nuclei 3.3.9 and nmap 7.93, and openly acknowledging technical limitations like IPv6 support. This transparency resonates with the security-conscious developer audience. While the technical depth is high, the contact page exhibits high sentence-length density, averaging 37.4 words per sentence, which can hinder readability. Adding meta descriptions to the checkout pages and breaking up multi-clause instructions would further refine the professional voice and improve search result consistency.

Evidence
Sentence Density
37.4 words/sentence
Technical Specificity
naabu 2.6.1
Meta Consistency
Missing on /pay

10 · Vertical credibility — tool transparency bypasses traditional dashboard fatigue

qsa.sh establishes vertical credibility by prioritizing terminal-native execution over bloated dashboards. The site meets security industry standards by explicitly naming its underlying engines and maintaining a strict nothing stored data policy. The utilitarian posture, reinforced by monospaced fonts and dark mode, creates an immediate insider feel for sysadmins. However, the site lacks traditional social proof, such as customer logos or third-party review scores. While the Transparency as Proof model is effective, adding quantitative signals like community traction signals or a Trusted by section would substantiate its status for less technical stakeholders.

Evidence
Tool Disclosure
nmap, nuclei, naabu
Data Policy
Zero retention
Social Proof
0 testimonials

11 · Competitive position — niche challenger trailing on content depth and authority

As a terminal-first utility, qsa.sh occupies a unique niche but faces significant challenges from established giants like Shodan and Censys. The site currently lacks the informational depth required to compete on broad keywords, possessing only seven pages compared to the massive content libraries of competitors like Pentest-Tools. With a domain age of less than one year, it also suffers from a lack of entity recognition and historical authority. To improve its standing, the site must bridge the content gap by creating landing pages for specific CVEs or tool outputs to capture long-tail security researcher intent.

Evidence
Content Scale
7 pages
Domain Age
< 1 year
Entity Presence
0 Wikipedia results

12 · Decision-support surfaces — transparent pricing grid with redundant technical axes

The pricing surface is a transparent, technical grid that avoids marketing fluff and clearly differentiates between one-off scans and monthly subscriptions. However, the table includes redundant information, such as the Nmap script row, which remains identical across all tiers and adds unnecessary cognitive load. On mobile devices, the three-column layout relies on horizontal scrolling, which frequently obscures the highest-margin Deep scan option. Implementing a stacked card layout for mobile and adding a Best for... recommendation callout would better guide users through the decision-making process without requiring them to parse every technical detail.

Evidence
Redundant Axis
Nmap script row
Mobile UX
Horizontal scroll
Price Tiers
$5/mo vs $7/scan

14 · Authority & link risk — clean 52/100 profile for a nascent 2026 domain

The site is a brand-new asset with a clean but empty backlink profile, having first been indexed in late July 2026. While it currently lacks external authority signals and citations, it avoids all common risk footprints like toxic outbound links or link-farm behavior. The internal link graph is efficient with a shallow click depth, but the site lacks equity hubs that naturally attract external links. Growth is currently bottlenecked by the new domain sandbox effect. Establishing a baseline of trust through technical directories and security tool aggregators is the primary requirement for building domain equity.

Evidence
Domain History
First seen July 2026
Click Depth
Max 2
External Mentions
0 results

15 · Off-page readiness — anonymous entity status hinders earned media potential

qsa.sh possesses a high-quality linkable asset in its curl command, but its off-page readiness is limited by an anonymous brand presence. The site lacks named founders, expert bios, or Person schema, which makes it less likely to be cited by journalists or security researchers. While Organization schema is present for Tuxxin, it lacks sameAs links to social profiles. Additionally, the technical guides lack OpenGraph metadata, reducing their shareability on social platforms. Transitioning from an anonymous tool to a verified brand entity with active social profiles is critical for unlocking earned media growth.

Evidence
Entity Links
0 sameAs links
Social Metadata
Missing OG tags
Trust Signals
Anonymous About page

16 · Rank readiness — 92/100 score for a clean, non-overlapping topic structure

qsa.sh is exceptionally well-structured for rank tracking, featuring distinct pages for every core topic. The site earns a 92/100 for rank readiness because its URL slugs are descriptive and there is zero evidence of internal keyword cannibalization. The primary challenge is the brand token itself; 'qsa' is a common acronym for Qualified Security Assessor in the PCI-DSS industry, which creates noise in search results. To maintain clarity, the brand must track 'qsa.sh' and 'curl qsa.sh' as its primary identifiers. The 'money' bucket is currently well-served by the homepage targeting 'external security scan' and 'ip vulnerability scan'.

Evidence
Rank readiness score
92/100
Cannibalization evidence
Zero

17 · Risk & stability — 94/100 stability with zero legacy domain baggage

The site is in a high-stability state with a 94/100 score, benefiting from its status as a new domain launched in July 2026. Crawl data confirms there are no critical indexability blockers or failed migrations, and the site is highly resilient to rendering issues because all metadata is present in the raw HTML. However, the site faces a medium exposure level to SERP erosion. Because it functions as a utility tool, it is vulnerable to 'zero-click' searches where AI Overviews might answer basic IP scanning queries. The current content is 100% concentrated on a single niche, which poses a risk during niche-specific algorithm updates. Diversifying into related security topics like CVE explainers and adding FAQ schema to the 'How it works' page will help capture more SERP real estate and hedge against these risks.

Evidence
Risk & stability score
94/100
Domain age
Launched July 2026

18 · Content briefs discipline — 76/100 score hampered by a 20% snippet paragraph rate

Existing content is technically sound but lacks the structural hooks required for modern answer engine optimization. The site earns a 76/100 because only 20% of its informational sections contain the 40-60 word definitional paragraphs suitable for Featured Snippets. While technical details are present, the site lacks structured comparison tables that drive citations in the security vertical. Internal linking also shows signs of 'anchor text monoculture,' with 70% of links using exact-match terms like 'pricing' or 'terms'. To improve, the site should add a 'What is qsa.sh?' summary to the top of the 'How it works' page to better capture informational intent.

Evidence
Content briefs score
76/100
Snippet paragraph rate
20%

19 · Editorial QA of content — 91/100 for manual QA and zero detected AI-slop tells

qsa.sh demonstrates rigorous editorial discipline, earning a 91/100 for content quality. The review found zero significant AI tells, such as bilateral framing or hedge stacking, and the voice remains consistent across marketing and technical documentation. Claims are backed by specific technical references to open-source projects like Nuclei and Nmap. The 'How it works' page is a model for transparency, using FAQ schema that perfectly synchronizes with the visible content. Minor QA issues are limited to the checkout process, where both the 'Full' and 'Deep' scan pages share the same 'Checkout — qsa.sh' meta title. Differentiating these titles and implementing a 301 redirect for the /pricing/ trailing slash variant are the only required editorial polishments.

Evidence
Editorial QA score
91/100
AI-slop tells
Zero

20 · Content program — 30/100 score due to 0 content-shaped URLs in the crawl

The site is currently operating in a 'utility mode' with no legible content program, resulting in a critical score of 30/100. The crawl discovered zero content-shaped URLs, such as a blog, resource center, or learning directory. This creates a high opportunity cost, as technical users often discover security tools while researching remediation steps for specific open ports. To capture this top-of-funnel interest, qsa.sh should initialize a /learn directory. High-leverage opportunities include creating a glossary for 'Commonly Exposed Ports' and technical guides on integrating the tool with CI/CD pipelines. Establishing a cadence of 1-2 technical pieces per month focusing on terminal security workflows would significantly improve the site's ability to capture high-intent search traffic from developers.

Evidence
Content program score
30/100
Content-shaped URLs
0

22 · Content freshness — 95/100 score with 100% of content modified within 30 days

qsa.sh maintains an exceptional freshness profile of 95/100, largely due to its recent launch. 100% of the crawled content was published or modified within the last 30 days, meaning the site currently carries zero staleness debt. The median page age is approximately 8 days, and there are no outdated year references or dead links across the 10-page library. Because the site is brand new, it does not yet require a complex governance framework, but it should establish a quarterly audit rhythm starting in 2026. Connecting Google Search Console now will allow the owner to monitor for future traffic decay and ensure that technical documentation, such as tool version references, stays aligned with the current security landscape.

Evidence
Content freshness score
95/100
Content modified within 30 days
100%

23 · Docs & self-serve help — 58/100 score for a flat FAQ structure lacking a changelog

While the technical content is high-quality, the site earns a weak 58/100 for documentation infrastructure. Help content is currently restricted to a single 'flat' FAQ on the /how-it-works page. This lacks the formal organization expected of a security tool, such as a searchable knowledge base or a public changelog. Security-conscious users require a changelog to track updates to the scanning engine and the addition of new vulnerability templates. Furthermore, the site mentions a '10,500-template set' but provides no searchable reference for what is actually tested. Migrating the FAQ to a dedicated documentation portal and adding an /llms.txt file would improve both user self-service and AI-driven discovery of the tool's capabilities.

Evidence
Docs & help score
58/100
Documentation paths found
0

24 · Measurement readiness — 70/100 score for privacy-first Umami tracking without event data

qsa.sh uses a clean, privacy-first measurement foundation with Umami, which is highly appropriate for its developer audience. However, the 70/100 score reflects a lack of intent data; the current implementation only tracks pageviews. The primary value-exchange—the 'curl qsa.sh' command—is not instrumented, meaning the owner cannot distinguish between a window shopper and an active user. To reach full measurement readiness, the site must instrument the 'Copy command' button and pricing tier clicks as custom events. Additionally, there is no evidence of conversion tracking for the PayPal checkout funnel. Implementing conversion event tracking for successful purchases is essential for calculating Customer Acquisition Cost and understanding the true activation rate of visitors.

Evidence
Measurement readiness score
70/100
Custom event payloads detected
0

25 · Technical SEO — 91/100 score for zero JS dependency and perfect host consolidation

The technical health of qsa.sh is exceptional, earning a 91/100. The site features perfect host consolidation and zero dependency on JavaScript for rendering, ensuring search engines can index all content immediately. Security headers are strong, utilizing TLS 1.3 and a robust Content-Security-Policy. The primary technical defects are minor configuration issues: URLs with a trailing slash, such as /pricing/, return a 200 status instead of a 301 redirect, which can split link equity. Additionally, the contact page is currently set to 'noindex', which prevents the site from ranking for branded support queries. Fixing these requires implementing a server-side redirect rule to strip trailing slashes and updating the contact page robots tag to 'index, follow'.

Evidence
Technical SEO score
91/100
JS rendering dependency
Zero

26 · On-page SEO — 88/100 score with unique titles but missing Product schema

qsa.sh exhibits strong on-page fundamentals with a score of 88/100. Titles and H1 tags are well-aligned with technical intent, and the site correctly front-loads keywords like 'External security scan'. However, the homepage meta description at 166 characters exceeds the recommended limit and risks truncation in search results. A more significant gap exists on the pricing page, which lacks Product structured data. Adding Product schema with Offer properties for the $5 and $7 tiers would enable price and score rich snippets in the SERPs. The site should also differentiate the meta titles for its checkout variants, which currently share a duplicate 'Checkout — qsa.sh' tag, to improve clarity in browser history and tab management.

Evidence
On-page SEO score
88/100
Homepage meta description length
166 characters

27 · Keyword targeting — 85/100 score for high clarity on 'external security scan'

The site earns an 85/100 for keyword targeting, showing high clarity on its primary transactional terms. It successfully captures intent for 'external security scan' and 'IP scan terminal', but it lacks middle-of-funnel 'comparison' content. In the cybersecurity vertical, comparison traffic is a high-converter; the absence of pages comparing qsa.sh to tools like Shodan or Censys is a missed opportunity. The keyword mix is currently balanced between transactional and informational intent, but the 'About' page has diffuse targeting, focusing on 'transparency' rather than the more searchable 'Transparent Security Scanning'. Creating a 'qsa.sh vs Shodan' comparison page and a technical glossary will help capture long-tail informational queries and commercial investigation traffic.

Evidence
Keyword targeting score
85/100
Comparison pages found
0

28 · Content portfolio health — 92/100 score for substantive 600-word median page depth

The content portfolio is lean but high-quality, earning a 92/100. All core pages are substantive, with a median length exceeding 600 words, and the 'How it works' page provides an impressive 1,172 words of technical context. No keyword cannibalization or thin content issues were detected among indexable pages. The primary hygiene issue is the 'noindex' directive on the contact page, which unnecessarily hides a high-trust surface from branded search results. Additionally, the pricing page's non-canonical trailing slash variant should be consolidated via 301 redirect to prevent potential duplicate content signals. Removing the noindex tag from /contact and differentiating the titles on the checkout pages will finalize the portfolio's health.

Evidence
Content portfolio score
92/100
Median page word count
>600

29 · Content gaps — zero comparison pages or research-stage guides

qsa.sh maintains a strong transactional core but remains invisible during the research and comparison phases of the buyer journey. While the terminal-first interface is a unique differentiator, the crawl identified zero pages targeting 'vs', 'alternatives', or 'best' queries. This forces the site to rely on direct brand awareness rather than capturing users comparing tools like Shodan or Censys. The 'How it works' page provides 1,172 words of technical depth but lacks specific use-case segmentation for audiences like home-labbers or VPS administrators. To bridge this gap, the site requires a dedicated comparison hub and a security knowledge base targeting technical 'how-to' queries.

Evidence
Comparison pages
0
How it works depth
1,172 words

30 · Keyword gaps — high-intent 'best scanner' terms uncontested

qsa.sh effectively owns the 'terminal IP scan' niche but fails to contest broader problem-aware keywords dominated by established competitors. Analysis shows that rivals like Pentest-Tools and HackerTarget dominate the 'best external vulnerability scanner' SERPs, while qsa.sh lacks content for high-volume 'how-to' searches such as 'scan public IP for vulnerabilities.' The site currently captures unique territory with 'curl qsa.sh' queries but misses the opportunity to target 'CLI security audit' or 'developer security tools.' Transitioning from a tool-only presence to a topical authority requires targeting these less crowded but highly relevant sub-niches through long-form technical guides.

Evidence
Shared territory
external security scan
Untapped volume
scan public ip for vulnerabilities

32 · AI search readiness — clean HTML hindered by missing llms.txt

The site is structurally optimized for AI extraction due to its zero-JS rendering and semantic HTML, yet it lacks critical machine-readable trust signals. While the answer-first prose on the homepage facilitates easy summarization, the absence of an llms.txt file at the root prevents AI agents from accessing a curated roadmap of the site's documentation. Furthermore, the 'unset' status of document versions on the terms page and the lack of dateModified properties in the JSON-LD schema signal a lack of freshness to answer engines. Implementing Person schema for the operator and adding explicit 'sameAs' links to professional profiles would resolve the current entity trust gap and solidify E-E-A-T.

Evidence
llms.txt status
404 Not Found
Document versioning
unset

33 · Fix-priority hygiene — noindexed contact page and cache-control issues

Technical hygiene is compromised by high-priority indexing and performance oversights that create unnecessary friction. The most critical failure is the 'noindex, follow' directive on the high-intent contact page, which prevents the site from capturing branded conversion traffic. Additionally, the homepage serves a 'private, no-store' cache-control header, unnecessarily increasing origin load and slowing repeat visits. Accessibility also requires immediate attention: the '.muted' CSS class fails WCAG AA contrast standards, and the suppression of focus indicators via 'outline: 0' creates barriers for keyboard-only users. Resolving these three items—indexing, caching, and contrast—represents the most immediate path to improved site health.

Evidence
Contact page status
noindex
Cache-Control header
private, no-store

34 · SEO composite coherence — 82/100 foundation limited by content gaps

The technical and on-page foundation of qsa.sh is exceptionally strong, yet its overall growth is bottlenecked by specific configuration errors and a thin content funnel. The site excels in performance and semantic structure but is undermined by the lack of middle-of-funnel comparison content and missing AI-readiness signals like llms.txt. Resolving these technical blockers is the primary requirement for building entity trust and capturing high-intent search queries. By addressing these quick wins and enriching the schema with dateModified properties and Organization 'sameAs' links, qsa.sh can leverage its clean technical base into significant search visibility.

Evidence
Composite score
82/100
AEO-GEO score
72

Verdict — 78.6/100: Strong technical utility with bottlenecks

qsa.sh is a high-performance utility that perfectly aligns with the mental model of security-conscious developers. Its primary strengths lie in its 93/100 performance score and 94/100 usability, driven by a minimal, text-heavy design that respects the user's time and technical expertise. The site successfully bypasses the 'bloated dashboard' trend by prioritizing terminal-native execution and tool transparency.

The product is currently held back by two fixable weaknesses: a critical lack of a content program (30/100) and technical configuration errors like the noindexed contact page. These issues prevent the site from capturing broader market interest beyond its immediate niche. Furthermore, the lack of middle-of-funnel comparison content makes it difficult for users to evaluate qsa.sh against established competitors.

This product is ideal for security engineers and sysadmins who prioritize terminal-native tools and transparency over complex enterprise interfaces.

Evidence
Usability Score
94/100
Performance Score
93/100

90-day roadmap

Window Action Modules Expected effect
Days 1-14 Remove noindex from /contact, fix cache-control headers, and adjust muted text contrast. seo-site-health-audit, seo-technical Unblock contact page indexing, improve TTFB via caching, and achieve WCAG compliance.
Days 15-45 Create 'qsa.sh vs Shodan' comparison page and add Product/FAQ schema to pricing and how-it-works. seo-content-gap-audit, seo-onpage Capture middle-of-funnel search intent and enhance SERP rich results.
Days 46-90 Implement /llms.txt, add Organization sameAs links, and build initial tech-stack backlist citations. seo-aeo-geo, seo-backlink-audit Establish machine-readability, entity trust, and baseline domain authority.
Evidence
Roadmap Actions
3

Methodology & data notes

This review is based on a crawl of 10 pages conducted on 2026-08-03. Data sources include raw HTML analysis, performance profiling, and accessibility audits. Several dimensions were excluded due to the site's current stage: 06 (Brand mark system), 08 (Imagery & art direction), and 21 (Distribution & reach). 13 (Review-content integrity) and 31 (Programmatic SEO quality) were marked as not applicable. Enrichment is currently pending for Google Search Console data. Detailed scoring criteria can be found at /methodology.

Evidence
Data Gaps
5 dimensions excluded

Questions buyers actually ask

Is qsa.sh suitable for professional security audits?

Yes. The tool uses industry-standard open-source components like nmap and nuclei, providing high transparency for security engineers who need to verify the underlying scan logic.

How does qsa.sh compare to Shodan or Censys?

While Shodan and Censys offer massive global datasets, qsa.sh focuses on frictionless, terminal-native execution for specific IP scans, catering to a 'terminal-first' developer workflow.

What are the main technical limitations of the site?

The site currently suffers from aggressive no-store caching headers and a noindexed contact page, which impacts performance efficiency and high-intent user conversions.

Is the service free to use?

The business model is freemium with a pay-per-scan option. The tool is highly accessible, and pricing is transparent for the available tiers.

How this review was made

SiteList crawled qsa.sh on August 3, 2026 — pages, screenshots, performance runs, structured data and public records — then scored it across 34 published dimensions. Every claim above cites crawl evidence; nothing is hand-tuned and the verdict is never for sale.

Not assessed on this crawl: 06 · logo-design, 08 · art-direction. Their weight was redistributed across the assessed dimensions.

Pending enrichment (data we could not fetch this run): serp_samples, Scripted Playwright execution of the /pay redirect to verify Stripe/PayPal handoff., google_psi_api, openpagerank, Ahrefs/Moz/Majestic API for referring domain counts, SERP mention sampling, Google Business Profile lookup (not applicable for SaaS), Podcast Index API

Read the full methodology

79/100qsa.sh — External security scan of your own IP, in your terminalJump to review