SiteRecon · accuracy
How SiteRecon is tested
Every change is checked by running the real audit over a set of small websites built to contain known problems, and the check fails if it misses them or reports problems that are not there. These are the results that were committed with this version of the code.
Seeded problems
- Test sites
- 9
- Problems found
- 48 of 48
- False alarms
- 0
- Recall
- 100.0%
- ✓ Every finding carries evidence from the page.
- ✓ Running the same site twice gives the same result.
- Last run 2026-10-06. The build fails below 95% recall or on any false alarm.
What these numbers do not show
- The 9 test sites are small pages built for the test. They are not a sample of the real web, so full marks here means the checks do what they say, not that every report about your site is right.
- Only the fixed checks are measured. The AI review, PageSpeed, social profile reads and competitor comparison need live services and are not part of this score.
- The AI review can move the content score by at most 20 points, and only with a quote from your page. That bound is tested below.
Attacks on the tool itself
10 of 10 cases held (last run 2026-10-06).
- ✓ hostile addresses are refused before any request
- ✓ a name that resolves to the cloud metadata address is refused
- ✓ a redirect to a private address is refused
- ✓ an enormous response is cut off at the size cap
- ✓ a response that never ends is cut off by the time limit
- ✓ an obedient model that fails everything cannot plant text, move the score far, or reach private names
- ✓ an obedient model that passes everything cannot plant text, move the score far, or reach private names
- ✓ forged fence markers in the page cannot close the untrusted block
- ✓ a bot-challenge page is reported, not audited
- ✓ a site that forbids crawlers is not scanned