Data sources
Every AuditHQ report is our own analysis. Below is what each engine measures and how, so you can judge the confidence a finding deserves — and the credits required by the licences of public data we build on.
How we measure
AuditHQ Lab
Every audit starts here. We request your page the way a visitor's browser would and measure what actually comes back: response time, transfer size, redirects, certificate handling, and the structure of the HTML itself.
Method · Direct measurement, performed by us on every run.
Deep Performance Scan
A deeper synthetic analysis of how the page loads and renders, producing the category scores you see alongside the lab figures.
Method · Synthetic analysis under controlled network and device conditions.
Real Visitor Data
How your site performed for real people, aggregated over a rolling 28-day window. When this disagrees with a synthetic score, this is the one that reflects what your visitors experienced.
Method · Aggregated, anonymised measurements from real browsers. Sites below a traffic threshold have no record yet — that is not a low score.
Component Intelligence
What your site is built from — platform, plugins, themes and libraries — identified from what the page publicly serves.
Method · Fingerprinting of the HTML and response headers we already fetched, cross-checked against public component registries.
AuditHQ Advisory Index
Published security advisories affecting the component versions we found on your site.
Method · Matching detected versions against consolidated public vulnerability records.
Review Intelligence
What people say about your app or site, condensed into themes, sentiment and the complaints that recur.
Method · Deterministic text analysis of public review and listing data. No generative model writes any part of your report.
Visual Change Tracking
A capture of your page on every run, compared pixel-by-pixel with the previous one so unintended visual changes surface on their own.
Method · Image capture and difference analysis performed by us.
What we will not do
- • We do not generate findings with a language model. Every score, check and recommendation comes from a measurement or a documented rule, so the same site measured twice gives the same answer.
- • We do not report a category we could not measure as a zero. An unmeasured category is shown as unmeasured.
- • We do not present an incomplete inspection as a clean result. Where coverage is partial, the report says so.
Attribution
Some of the public data we build on is licensed on condition that it is credited. Those credits are here.
- Security advisories
Advisory records incorporate data from the GitHub Advisory Database, used under the Creative Commons Attribution 4.0 International licence.
CC-BY-4.0 · Source
Measurement methods change as we improve them. This page is updated when they do.