FAQ
Questions, answered.
What the audit checks, what it doesn’t, and what happens to your data.
The audit
What does Critical Audit actually check?
Every audit scores six categories, two under each of three pillars:
Revenue — what the site earns
- Visibility — whether customers can find you on Google and in AI answers (ChatGPT, Gemini, Perplexity)
- Conversion — how much of your traffic turns into enquiries or sales
Risk — what can hurt or sue you
- Security — exposure to breaches, data loss and downtime, including known CVEs and out-of-date software you run
- Compliance — GDPR, cookies, and the European Accessibility Act, in force since June 2025
Experience — what customers feel
- Speed — every extra second of load time costs conversions
- Usability & design — where visitors get confused, stuck, or leave
You get one overall score, a score per category, and every finding ranked by what it costs you.
How long does an audit take?
Usually a couple of minutes. We fetch your pages, run the full analysis, then email you a link to your report. You see a preliminary score on screen while it runs, and the full report opens in your browser — every finding ranked, with what it takes to fix it. Nothing to download, and the link keeps working, so you can send it to whoever does the work.
Do I need to install anything on my site?
No. The audit runs entirely from the outside, exactly the way a visitor — or a search engine — sees your site. There is no plugin, no script tag and no access to your server or admin panel.
Do I need an account?
No account, no password, no signup flow. Enter a URL and an email address, and the report comes to your inbox.
WordPress
How do you find WordPress vulnerabilities?
We fingerprint the WordPress core version plus the plugins and themes your site exposes publicly, then match that inventory against a continuously synced mirror of published advisories. Nothing is guessed from a version number alone — the affected version ranges in each advisory are matched precisely.
Will you tell me if a new vulnerability affects my site later?
Yes. Audited sites stay in our registry with their last-seen software inventory. When a new advisory lands that matches something you are running, we email you an alert — even if your audit was weeks ago.
Privacy
What do you do with my email address?
We use it to send your report and to alert you if a new vulnerability affects your site. Nothing else reaches that address unless you ask for it: the monthly brief is a separate list you have to tick, kept apart from your alerts and with its own unsubscribe. No list rental, no resale, either way.
Can I audit a site I do not own?
The audit only reads what any visitor can already load, so it is technically possible — but the report is written for the person who can act on it. If you are auditing a client or prospect site, send it to yourself.
Pricing
Is it really free?
The automated audit and the full report are free. If you want someone to actually fix what the report finds, get in touch — that part is the business.