DocumentationSearch docs
  1. 01Getting started
  2. 02Scanning
  3. 03Checks
  4. 04Services
  5. 05Configuration
  6. 06Ignoring checks
  7. 07CI
  8. 08Agent skill
  9. 09Dashboard
  10. 10Supported stacks

Checks

Checks

Every check has an ID: use it with --only and --skip, in the ignore: list of preflight.yml, and with preflight ignore. preflight checks prints them all. Checks marked opt-in stay off until you enable them in preflight.yml.

SEO and social

ID What it checks
seo_meta A title and description, and Open Graph tags
og_twitter og:image, twitter:card and the rest of the social sharing metadata
canonical A canonical link tag
structured_data JSON-LD Schema.org markup
viewport A viewport meta tag for mobile
lang The lang attribute on <html>, for accessibility
index_now An IndexNow key file, for faster search indexing. Opt-in

Security and infrastructure

ID What it checks
security_headers HSTS, CSP and X-Content-Type-Options, on production and staging
ssl That the SSL certificate is valid, with a warning before it expires
www_redirect That www and the bare domain redirect to the canonical one
secrets API keys and credentials committed to the code
email_auth SPF and DMARC DNS records for your domain. Opt-in

Environment and health

ID What it checks
env_parity Variables in .env.example that are missing from .env
health_endpoint That the site answers. It tries /health, /healthz and /api/health, then the root

Code quality and performance

ID What it checks
vulnerability Dependency vulnerabilities, through your package manager’s own audit
debug_statements console.log, var_dump, debugger and the like left in the code
error_pages Custom 404 and 500 pages
image_optimization Images over 500KB
ID What it checks
legal_pages A privacy policy and terms of service

Cookie consent tools are checked as services.

Web standard files

ID What it checks
favicon A favicon, an apple-touch-icon (.png, .webp or .svg) and a web manifest
robots_txt A robots.txt with something in it
sitemap A sitemap.xml, or a generator that makes one
llms_txt An llms.txt for AI crawlers
ads_txt An ads.txt, for ad-supported sites. Opt-in
humans_txt A humans.txt crediting the team. Opt-in
license A license file, for open source projects. Opt-in

Check IDs renamed in 0.22

Every check ID is now snake_case. The old camelCase names keep working everywhere an ID is accepted (ignore: lists, --only, --skip and preflight ignore) through the 1.x line, with a note on stderr, and go away in 2.0. preflight ignore writes the new name. The keys under checks: in preflight.yml (healthEndpoint, seoMeta and so on) are a separate schema and did not change.

Old New
seoMeta seo_meta
ogTwitter og_twitter
securityHeaders security_headers
envParity env_parity
healthEndpoint health_endpoint
robotsTxt robots_txt
llmsTxt llms_txt
adsTxt ads_txt
humansTxt humans_txt
indexNow index_now

Scanning code you don’t trust

Every check reads files; one runs a program. The vulnerability check runs your project’s own package manager (npm audit, yarn audit, composer audit, bundle audit, pip-audit, govulncheck or cargo audit) inside the project directory, with a scrubbed environment and a temporary home so it cannot read your tokens.

Package managers still honor project-local configuration, and some of that configuration can run code from the repository (a Yarn yarnPath, a Cargo alias, a Composer plugin). Scanning your own projects is what Preflight is for. When you scan a repository you don’t trust, such as a fork’s pull request in CI, add --skip vulnerability.