REVIEW METHOD
How is a website reviewed?
MaxAuditor Pro separates the signals it actually observes instead of presenting one unsupported verdict. This page explains the order of the scan and where the result has practical limits.
1. Target validation
The submitted address is parsed with standard URL rules. Only HTTP and HTTPS are accepted; URLs with user information, private-network targets, and ports that do not fit a normal public web review are rejected.
IPv4 and IPv6 results are evaluated together during DNS resolution. Once a target is approved, the connection is made to a validated IP rather than trusting a later hostname lookup. This reduces the DNS-rebinding window between validation and connection.
2. Redirect chain
Redirects are not handed to the HTTP client without checks. Every 3xx Location value is parsed again and the protocol, hostname, port, DNS, and IP policy is rerun for the new target.
The chain is kept within a fixed hop limit. A public site that redirects to localhost, link-local space, cloud metadata, or a private network is stopped safely.
3. Connection and main response
The report records status, final URL, response time, content type, HTTPS behavior, and important HTTP headers. HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are reviewed from the values that are actually returned.
Responses are not read into memory without bounds. Resource-specific byte limits and timeouts are applied, and decompressed output is counted when compressed responses are expanded.
4. Privacy and measurement signals
The main HTML is checked for privacy and cookie links, preference controls, and common measurement tags. Set-Cookie headers are summarized for Secure, HttpOnly, and SameSite attributes.
Provider-side consent settings cannot always be confirmed from public markup. The report stays within the evidence it can see; browser developer tools and the provider dashboard may be needed for a second check.
5. Search and discovery
The scanner reads the title, description, canonical URL, hreflang, robots meta directives, Open Graph fields, and structured-data types. It also checks known files such as robots.txt, sitemap.xml, the web manifest, and security.txt.
A reachable file does not guarantee indexing or ranking. Search services combine crawlability with content value, site signals, and their own ranking systems.
6. Scores and severity
The score is a compact way to sort many findings. A critical or high finding deserves earlier attention, but its real impact still depends on the site architecture and use case.
Read the observed evidence before optimizing for the number. After a configuration change, scan the same production URL again and confirm that the public value really changed.
7. Reproducibility and records
Exports retain the scan time, final address, and redirect chain. That makes it easier to compare the public response before and after a deployment.
CDN location, cache state, regional content, and third-party tags can change over time. A scan is an observation from its recorded moment and should not replace a fresh production check.