POST /website-auditWebsite Auditor
Inspect a public website for structure, metadata, links, content quality, trust signals, mobile readiness, and operational defects.
A complete audit layer for websites, APIs, AI agents, x402 payment routes, security posture, claims, data, performance, accessibility, and full digital systems. Every check is bounded, non-destructive, scored, and returned with evidence and ranked remediation.
Buy only the inspection you need or call the Full Stack Audit Orchestrator to coordinate multiple domains. Paid execution is routed through the existing Apex exchange; unpaid requests receive HTTP 402.
POST /website-auditInspect a public website for structure, metadata, links, content quality, trust signals, mobile readiness, and operational defects.
POST /api-auditTest a public API endpoint for response behavior, schema quality, status handling, headers, latency, and contract defects.
POST /security-auditPerform a non-destructive security posture review covering transport, headers, exposure, secrets, redirects, and common misconfiguration signals.
POST /x402-auditVerify x402 payment-gate behavior, payment metadata, network declarations, unpaid response quality, and settlement-route consistency.
POST /agent-auditEvaluate an AI agent or application for discoverability, manifest quality, bounded behavior, truthful capability claims, and machine usability.
POST /compliance-auditReview supplied public claims, disclosures, policies, and operating language for unsupported assertions, missing notices, and avoidable compliance risk.
POST /data-auditAnalyze JSON or tabular records for completeness, duplication, type drift, invalid values, outliers, and field-level quality defects.
POST /performance-auditMeasure bounded endpoint latency, payload size, cache behavior, compression signals, and repeat-request consistency.
POST /accessibility-auditInspect public HTML for accessibility, semantic structure, keyboard and form signals, readable metadata, and usability defects.
POST /full-auditCoordinate a complete multi-domain audit, combine evidence, score the system, rank remediation, and produce an executive report.
Every report includes a 0–100 score, letter grade, verdict, severity counts, evidence, remediation, limitations, timestamp, and stable audit ID.
The network audits public surfaces and customer-supplied data. It does not conduct destructive testing, brute force, port scanning, credential attacks, exploitation, persistence, or stealth.
Reject local, private, credential-bearing, and non-HTTPS targets.
Run limited requests with strict timeouts, methods, payload caps, and redirect controls.
Convert deterministic findings into severity, score, grade, and verdict.
Rank defects and state the corrective action without theatrical guessing.
Return the report and store an operational receipt in D1.
Example paid route: https://apex-agent-exchange.keenanbooker83.workers.dev/audit/full-audit. Send JSON containing at minimum {"url":"https://public-target.example"}. The unpaid request returns the x402 challenge; the settled request is forwarded privately to the audit Worker.