Checks
Checks
Every check has an ID: use it with --only and --skip, in the ignore: list of preflight.yml, and with preflight ignore. preflight checks prints them all. Checks marked opt-in stay off until you enable them in preflight.yml.
| ID |
What it checks |
seo_meta |
A title and description, and Open Graph tags |
og_twitter |
og:image, twitter:card and the rest of the social sharing metadata |
canonical |
A canonical link tag |
structured_data |
JSON-LD Schema.org markup |
viewport |
A viewport meta tag for mobile |
lang |
The lang attribute on <html>, for accessibility |
index_now |
An IndexNow key file, for faster search indexing. Opt-in |
| ID |
What it checks |
security_headers |
HSTS, CSP and X-Content-Type-Options, on production and staging |
ssl |
That the SSL certificate is valid, with a warning before it expires |
www_redirect |
That www and the bare domain redirect to the canonical one |
secrets |
API keys and credentials committed to the code |
email_auth |
SPF and DMARC DNS records for your domain. Opt-in |
| ID |
What it checks |
env_parity |
Variables in .env.example that are missing from .env |
health_endpoint |
That the site answers. It tries /health, /healthz and /api/health, then the root |
| ID |
What it checks |
vulnerability |
Dependency vulnerabilities, through your package manager’s own audit |
debug_statements |
console.log, var_dump, debugger and the like left in the code |
error_pages |
Custom 404 and 500 pages |
image_optimization |
Images over 500KB |
| ID |
What it checks |
legal_pages |
A privacy policy and terms of service |
Cookie consent tools are checked as services.
| ID |
What it checks |
favicon |
A favicon, an apple-touch-icon (.png, .webp or .svg) and a web manifest |
robots_txt |
A robots.txt with something in it |
sitemap |
A sitemap.xml, or a generator that makes one |
llms_txt |
An llms.txt for AI crawlers |
ads_txt |
An ads.txt, for ad-supported sites. Opt-in |
humans_txt |
A humans.txt crediting the team. Opt-in |
license |
A license file, for open source projects. Opt-in |
Every check ID is now snake_case. The old camelCase names keep working everywhere an ID is accepted (ignore: lists, --only, --skip and preflight ignore) through the 1.x line, with a note on stderr, and go away in 2.0. preflight ignore writes the new name. The keys under checks: in preflight.yml (healthEndpoint, seoMeta and so on) are a separate schema and did not change.
| Old |
New |
seoMeta |
seo_meta |
ogTwitter |
og_twitter |
securityHeaders |
security_headers |
envParity |
env_parity |
healthEndpoint |
health_endpoint |
robotsTxt |
robots_txt |
llmsTxt |
llms_txt |
adsTxt |
ads_txt |
humansTxt |
humans_txt |
indexNow |
index_now |
Every check reads files; one runs a program. The vulnerability check runs your project’s own package manager (npm audit, yarn audit, composer audit, bundle audit, pip-audit, govulncheck or cargo audit) inside the project directory, with a scrubbed environment and a temporary home so it cannot read your tokens.
Package managers still honor project-local configuration, and some of that configuration can run code from the repository (a Yarn yarnPath, a Cargo alias, a Composer plugin). Scanning your own projects is what Preflight is for. When you scan a repository you don’t trust, such as a fork’s pull request in CI, add --skip vulnerability.