Troja vs. checkvibe, OffURL, Fixnx, SiteShield, CyScan, Dr URLs
A source-dated comparison of Troja, checkvibe, OffURL, Fixnx, SiteShield, CyScan.io and Dr Urls across scan scope, evidence, AEO and remediation.

Short version: Troja and checkvibe publish security, SEO and AEO workflows with AI-assisted remediation; both now describe connected analysis, though Troja advertises more provider categories. Fixnx is a bounded public security + SEO + performance scan with evidence and retesting. CyScan.io is free attack-surface reconnaissance. Dr Urls emphasizes broad website health and trends. OffURL is a no-account public report with active requests and explicit raw-HTML/no-auth limits. SiteShield packages broad public-site, AEO/GEO, accessibility and ESG signals for stakeholder reporting. The right tool follows the artifact and access scope you need.
If you ship with AI coding tools, the question is not just “which score is largest?” It is whether the scanner can produce reproducible evidence for your public surface, connected configuration and search or answer-visibility goals—and clearly label what it did not test.
How we compared
We reviewed each vendor's current first-party product material on July 18, 2026 and mapped the published scope to jobs a builder needs: inventory, observe, prioritize, remediate and retest. Capability labels below are vendor-attributed; they are not results of an independent penetration test. Live plan pages remain the source for prices and entitlements.
Feature comparison at a glance
| Capability | Troja | checkvibe | OffURL | Fixnx | SiteShield | CyScan.io | Dr URLs |
|---|---|---|---|---|---|---|---|
| Published public scan | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ recon | ✅ health |
| Security + SEO | ✅ | ✅ | ✅ published categories | ✅ | ✅ | Recon focus | ✅ |
| AEO / AI visibility advertised | ✅ | ✅ | Not on reviewed page | Not on reviewed page | ✅ AEO + GEO | Not on reviewed page | Not on reviewed page |
| Accessibility advertised | Not a core category | Not a core category | ✅ | Not on reviewed page | ✅ | Screenshots, not an audit | ✅ |
| Connected analysis advertised | ✅ 6 provider categories | ✅ GitHub + Supabase | Public/raw HTML | Public scan | Public-site scope | Public recon | Public-site health |
| Active or authenticated boundary | Active workflow published | Verify current scope | Active requests; no auth | Bounded public requests | Public-site scope | Recon requests | Public-site checks |
| Developer integration advertised | MCP + API | MCP + API | Report workflow | Report + retest | Report/remediation | Shareable recon | Monitoring/trends |
| Best-fit artifact | Fix queue + client report | Connected scan + fixes | One public report | Evidence-led snapshot | Stakeholder audit | Surface inventory | Health baseline |
Legend: ✅ yes · ⚠️ partial / different scope · ❌ no.
Troja vs. checkvibe: the closest call
checkvibe shares Troja's security + SEO + AEO and AI-remediation positioning. Its current official material publishes 100+ security, 68 SEO and 46 AEO checks, URL scans, connected GitHub/Supabase analysis, PDF export, MCP/API access and monitoring. The numbers are vendor-published and source-dated here, not treated as permanent product limits.
Troja publishes additional connected categories—Stripe, Vercel, Railway and Resend—alongside GitHub and Supabase, plus white-label and verify-fix workflows. checkvibe also publishes connected GitHub and Supabase analysis. Compare read-only permission scopes and finding evidence on the same project.
Pick checkvibe when its URL/GitHub/Supabase workflow and current AEO implementation match your team. Pick Troja when its additional providers and reporting/retest workflow matter. See the full Troja vs. checkvibe breakdown.
Troja vs. OffURL
OffURL publishes 150+ checks and a no-account, report-by-report workflow. Its security-heavy categories include active public requests, CVE/threat context, email authentication, accessibility and domain intelligence. The vendor explicitly says it analyzes raw HTML without JavaScript rendering, does not authenticate, may trigger firewalls and requires manual verification.
Versus Troja: OffURL's reviewed material does not advertise AEO, connected providers or an ongoing MCP/monitoring workflow. Its bounded public report is a different artifact, with limitations stated clearly. See the full Troja vs. OffURL breakdown.
Pick OffURL for a self-contained public assessment. Pick Troja when you also need answer visibility, connected context and an ongoing fix loop.
What is Fixnx, and how does it compare to Troja?
Fixnx publishes 120+ bounded public checks across security, SEO and performance, with evidence, severity, confidence and retesting. Its current workflow describes one free scan and paid scan packs; use the live purchase page for current terms.
Its reviewed product page does not advertise AEO or named connected-provider analysis. It also states that automated scanning still needs manual testing for deeper risks.
Pick Fixnx for a quick, evidence-led public security + SEO + performance snapshot. Pick Troja when AEO, connected providers or an editor/monitoring loop matter. See the full Troja vs. Fixnx breakdown.
Troja vs. CyScan.io
CyScan.io is a free "cyber URL scanner," and it's excellent at its job: endpoint discovery, passive-DNS subdomain enumeration (via crt.sh, CertSpotter and HackerTarget), directory fuzzing, redirect-chain analysis, tech-stack detection and multi-device screenshots. It's a recon / attack-surface tool for security researchers — by its own description it isn't a full-stack vulnerability scanner.
That means no SEO or AEO scoring, no prioritised remediation, no AI fix prompts and no monitoring. It maps; it doesn't fix.
Pick CyScan.io to map an attack surface for free. Pick Troja when you need ranked findings plus AI fixes you can actually ship. See the full Troja vs. CyScan.io breakdown.
Troja vs. Dr URLs
Dr Urls is a website-health checker whose current site publishes 200+ checks across SEO, security, performance and accessibility, plus link intelligence, recurring analysis and before/after trends.
Its reviewed public material emphasizes health reporting rather than AEO, named connected providers or an editor-native remediation loop. Confirm any additional scope directly with the vendor.
Pick Dr URLs for broad site health plus accessibility and link monitoring. Pick Troja for AI-native security and AEO you can fix from your editor. See the full Troja vs. Dr URLs breakdown.
Troja vs. SiteShield
SiteShield publishes a broad public-site assessment for organizations and agencies. Its current material covers security, performance, technical SEO, accessibility, analytics/consent, AEO, GEO, ESG and four named AI-visibility perspectives: Perplexity, ChatGPT, Gemini and Claude. Reports and remediation are central to the offer.
Versus Troja: SiteShield's reviewed public scope is a stakeholder-oriented public-site report and remediation service. Troja publishes connected-provider and editor-integration workflows. See the full Troja vs. SiteShield breakdown.
Pick SiteShield if you're an agency or institution wanting a broad, presentable audit (GEO + ESG + accessibility). Pick Troja if you're a builder who wants to find it, understand it and fix it yourself.
Where Troja differentiates in this shortlist
- Broader published connected-provider coverage. Troja names GitHub, Supabase, Stripe, Vercel, Railway and Resend. checkvibe also names GitHub and Supabase, so connected analysis is not unique to Troja.
- An editor-native fix loop. A specific AI fix prompt per finding, an MCP server + API (shared only with checkvibe), verify-fix re-tests, scan-to-scan diffs and a branded executive scorecard.
- Full white-label client reports — your logo, name and colour on the report a client opens (SiteShield offers a verified badge; checkvibe doesn't white-label at all).
- Actionable AEO/GEO — per-bot snippet grading, an llms.txt generator and content-gap rewrite prompts. SiteShield reports AEO/GEO; Troja turns each gap into a prompt you paste into Cursor.
Which scanner should you choose?
- You want AI-answer-engine visibility, AI fix prompts and your real backend scanned → Troja.
- You want checkvibe's current GitHub/Supabase and AEO workflow → checkvibe.
- You want a bounded, no-account public report with explicit limitations → OffURL.
- You want an evidence-led public security + SEO + performance snapshot → Fixnx.
- You're an agency/institution wanting a broad, presentable audit with GEO + ESG → SiteShield.
- You want free attack-surface and subdomain recon → CyScan.io.
- You want broad site-health plus accessibility and link monitoring → Dr URLs.
There is no single “best” scanner. Choose the role, verify the evidence, document exclusions and combine tools where one layer cannot answer the next.
How to run a defensible seven-tool bake-off
A comparison page narrows a shortlist; it cannot reproduce your architecture. Run finalists against one authorized staging target and grade the artifacts they produce. Use a weighted sheet: reproducible evidence (30%), coverage of your actual public and connected surface (25%), remediation specificity (20%), retest and monitoring workflow (15%), and export/integration fit (10%). Do not award points for a check count unless the vendor explains what was requested, observed and excluded.
Seed three known, reversible conditions—a missing response header, a deliberately non-indexed test page and a harmless metadata defect—then confirm detection and cleanup. Add one authenticated authorization test manually because every public scanner has a blind spot there. Record plan limits and prices from live vendor pages on the evaluation date; do not carry a copied currency table into procurement.
The most reliable stack often combines roles: reconnaissance to map owned hosts, a public scanner to observe production behavior, a connected code/configuration review, dependency analysis in CI and periodic human testing. Choose the smallest combination that closes your documented risks rather than the product with the largest marketing number.
Frequently asked questions
Which tools in this comparison publish AEO or AI-visibility capabilities?
As of the July 18, 2026 source review, Troja, checkvibe and SiteShield publish AEO or AI-visibility capabilities. The vendors define and test those categories differently, so compare evidence rather than assuming equal labels mean equal coverage.
Which tool is best for free attack-surface reconnaissance?
CyScan describes a free, no-registration workflow for endpoint discovery, passive-DNS sources, directory fuzzing, redirects, assets and screenshots. Use it on authorized targets as an inventory input, not a security certification.
Which scanners can inspect something beyond a public URL?
Troja describes multiple connected providers, while checkvibe explicitly describes connected GitHub and Supabase scans. Compare the exact read-only scopes and evidence each integration returns.
Do any of these scanners replace a penetration test?
No. Their repeatable automated evidence is useful, but authenticated authorization, business logic and chained attack paths need manual verification. Fixnx and OffURL explicitly publish versions of this limitation.
How should prices be compared?
Open each vendor's live plan or checkout page on the decision date and record project limits, scan cadence, integrations, exports and retention alongside price. This guide avoids a frozen price grid because currencies and entitlements change independently.
Sources and verification notes
Product capabilities are vendor-attributed and source-dated. Technical guidance uses primary documentation or vendor-neutral standards.
- checkvibeOfficial capability source; reviewed July 18, 2026.
- OffURLOfficial capability and limitation source; reviewed July 18, 2026.
- FixnxOfficial scan-scope and evidence-model source; reviewed July 18, 2026.
- SiteShieldOfficial public-site assessment source; reviewed July 18, 2026.
- CyScanOfficial reconnaissance capability source; reviewed July 18, 2026.
- Dr UrlsOfficial website-health capability source; reviewed July 18, 2026.
- OWASP ASVSVendor-neutral requirements baseline for controls that automated public scans cannot fully verify.
Run the scan this post is about.
Free, no signup. See what's hiding inside your walls in ~30 seconds.
Keep reading
All posts
Best Website Security Scanners in 2026: Troja vs OWASP ZAP vs Snyk vs Burp Suite
A practical comparison of four very different tools — Troja, OWASP ZAP, Snyk, and Burp Suite — what each is actually for, and how to pick the right one for your stack.
Read
How to Check If Your Website Is Secure (5-Minute Guide)
A fast, do-it-yourself pass over the security basics every site should get right — TLS, headers, exposed files, and cookie flags — with the exact commands to check each.
Read
SaaS Security Checklist Before Launch: The MVP Guide
Shipping your MVP this week? Run this pragmatic, prioritized security pass first — covering auth, multi-tenancy, secrets, payments, and the few headers that actually matter.
Read