Security · Compliance · Accessibility

Your website has
vulnerabilities.

Paste a URL. In 3 minutes, we find what attackers and regulators would find — exposed credentials, outdated CVE libraries, GDPR gaps, ADA violations, and more. No setup required.

Free to try · No credit card required · Results in 3 minutes

+
scans completed
~3 min
average scan time
13+
attack vectors detected
OWASP
security framework
GDPR + ADA
compliance standards
🔒complixai.org/report/abc123
74
/ 100
Critical Risk
Scan results for
https://example-shop.com
Stripe API key exposed in page source. jQuery 2.1.4 loaded with active CVE. Session cookies missing HttpOnly flag. Plus 14 accessibility violations and a missing GDPR consent banner.
Security
Critical
Accessibility
High
Privacy
High
Legal Pages
Medium
eCommerce
Low
Marketing
Medium
🔴 Critical — fix immediately
1

Stripe secret key exposed in page source

sk_live_... found in inline JavaScript. Anyone viewing your source can use it. Rotate immediately and move server-side.

🔒

Security scanning — now included in every scan

We check for exposed API keys & credentials, outdated libraries with known CVEs, insecure cookie flags, missing security headers, CORS misconfigurations, admin panel exposure, and more — automatically, alongside every compliance check.

🔑 Exposed credentials
📚 CVE libraries
🍪 Cookie security
🛡️ Security headers

Compatible with every platform you use

WordPress
Shopify
Webflow
Next.js
React
Vue
Wix
Squarespace
Ghost
Framer
Angular
Nuxt

+ any platform that renders in a browser

[ 01 / 03 ]

Measurable Results

Security and compliance
clarity in minutes.

~3min
average scan time
start to report
13+
attack vectors checked
per security scan
100%
automated
no manual review

How it works

STEP 1·~5 seconds

Paste your URL

Enter your website address. No SDK, no code changes, no setup required.

Works with any web technology — React, WordPress, Shopify, or plain HTML.

STEP 2·~2–3 minutes

AI scans your site

Our scanner crawls every page and runs six compliance modules in parallel.

Accessibility, privacy, legal pages, eCommerce, security headers, and email compliance — all at once.

STEP 3·Instant

Get your report

Complix AI synthesises findings into plain English with exact fixes and a risk score.

Download as PDF or share a link. Risk score, category breakdown, and prioritised issues — ready immediately.

Scroll to continue

Security + Compliance Audits

Find what attackers
and regulators find.

Accessibility ViolationsComplix AI
IssuePagesSeverity
Images missing alt text8 pagesCritical
Low color contrast ratio14High
Missing ARIA labels on forms3Medium
No skip navigation1Low

Accessibility

WCAG 2.1 AA checks via axe-core — the industry standard used in ADA litigation.

Privacy & TrackersComplix AI
IssuePagesSeverity
Google Analytics loads pre-consentAllCritical
Facebook Pixel no consent gateAllCritical
Hotjar session recording active5High
Cookie banner not dismissible1Medium

Privacy

GDPR, CCPA, ePrivacy — trackers caught before regulators find them.

Legal PagesComplix AI
IssuePagesSeverity
No Refund Policy page foundCritical
Privacy Policy has placeholder text1High
ToS not linked in footer1Medium
Cookie Policy missingHigh

Legal Pages

Terms, Privacy Policy, Refund Policy — existence and content integrity checks.

Security VulnerabilitiesComplix AI
IssuePagesSeverity
Stripe key exposed in page sourceAllCritical
jQuery 2.1.4 loaded (CVE-2020-11022)3High
Session cookies missing HttpOnly flagAllHigh
CSP header absent — XSS unblockedAllHigh

Security

Exposed credentials, outdated CVE libraries, cookie flags, headers — 13 attack vectors.

Privacy-first

Your data stays yours.

We audit from the outside — no login required, no access to your source code, no stored credentials.

No login required

We scan exactly like a real user would

Isolated scans

Fresh crawl each run, nothing cached

Data retention

Delete any scan or report at any time

GDPR compliant

We practice what we audit on your behalf

What we check

Six legal risk categories

Each mapped to real regulations and real fines. No fluff, no false positives.

Free

Accessibility

WCAG 2.1 AA audit via axe-core. Screen-reader blockers, contrast failures, missing ARIA labels.

🍪
Pro

Privacy & Cookies

Tracker detection, consent banner presence, GDPR and CCPA coverage in your Privacy Policy.

📄
Business

Legal Pages

Terms of Service, Privacy Policy, Refund Policy. Existence checks and placeholder text detection.

🛒
Business

eCommerce

Return policy visibility, subscription billing disclosures, and hidden fee patterns.

🔒
Business

Security & Vulnerability Scan

Exposed credentials, outdated CVE libraries, insecure cookies, CORS misconfigs, SRI, admin panel exposure, mixed content, dangerous JS — 13 attack vectors checked.

📧
Business

Email & Marketing

CAN-SPAM, GDPR consent, TCPA SMS disclosures, pre-checked opt-in boxes.

Example output

Every issue includes a fix

Not just "you have a problem." Complix AI tells you exactly what to do, with code snippets where applicable.

Critical

No cookie consent banner detected

Why this matters

Your site loads Google Analytics and Meta Pixel before asking visitors for consent. Under GDPR Article 7, this can result in fines up to 20M euros or 4% of global annual turnover.

How to fix it

<!-- Add before any analytics scripts -->
<script id="Cookiebot"
  src="https://consent.cookiebot.com/uc.js"
  data-cbid="YOUR-CBID"
  type="text/javascript" async>
</script>

Self-check

How compliant is your site?

Answer 5 quick questions to get an estimated compliance score — then scan your real site to see the full picture.

01

Do you have a cookie consent banner that blocks trackers until the user accepts?

02

Is your Privacy Policy up-to-date and linked in your footer?

03

Do all images on your site have descriptive alt text?

04

Do you have Terms of Service and a Refund Policy linked from checkout?

05

Does your site send security headers like CSP and HSTS?

0 of 5 answered

Social proof

Founders sleep better.

Found a GDPR violation in our checkout flow that our legal team had missed for 6 months. Fixed it the same day.

SK

Sarah K.

CTO, SaaS startup

94
score after

We got hit with an ADA lawsuit demand last year. Now I run Complix on every deploy. Haven't had a single accessibility complaint since.

MT

Marcus T.

Founder, eCommerce brand

81
score after

The report caught that our cookie banner wasn't actually blocking scripts — it was just decorative. That's the kind of thing you don't catch manually.

PL

Priya L.

Head of Engineering

88
score after

Pricing

Simple, honest pricing

Start free. Upgrade when you need more coverage.

Free

$0forever
  • 1 scan ever
  • Accessibility check only
  • Risk score (0–100) only
  • No issue details or fixes
  • No PDF export
Start for free

Starter

$20/month
  • 5 scans per month
  • Full accessibility report
  • Issues listed with explanations
  • No code fix suggestions
  • No PDF export
Get Starter
Most popular

Pro

$49/month
  • Unlimited scans
  • Full accessibility report
  • Code fix suggestions
  • Privacy & cookie compliance
  • PDF export
Get Pro

Business

$149/month
  • Everything in Pro
  • Legal pages, eCommerce, security
  • Email & marketing compliance
  • White-label PDF reports
  • Priority support
Get Business

All paid plans include a 14-day money-back guarantee. Cancel anytime. No contracts.

Full feature comparison

FeatureFreeStarterProBusiness
Scans per month1 ever5UnlimitedUnlimited
Accessibility (WCAG 2.1)Score onlyFull reportFull reportFull report
Code fix suggestions
Privacy & cookies (GDPR)
Legal pages check
eCommerce compliance
Security headers
Email & marketing (CAN-SPAM)
PDF export
White-label PDF
Scheduled rescans
Priority support

Ready to audit your site?

Join developers and founders who audit their sites before lawyers do.

Scan your website free

No credit card required · Results in ~3 minutes