Website intelligence
via API
Technology stack, security headers, DNS infrastructure, and performance data for any domain. One request, structured JSON response.
What you get per domain
One API call returns structured data across six categories.
Technology Stack
CMS, frontend framework, CDN, analytics, payments, chat, error tracking, tag managers. Detected from headers, cookies, DNS, and HTML.
Security Posture
TLS version, certificate issuer, HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
DNS & Infrastructure
DNS provider, hosting region, MX provider category, SPF/DMARC presence, IPv6 support, SAN domains from TLS certificate.
Performance
TTFB, page size, compression type, HTTP/2 support, redirect chain count, DNS/TCP/TLS timing breakdown.
SEO Signals
robots.txt analysis, sitemap page count, canonical tags, hreflang languages, structured data types, publishing frequency.
AI Crawl Policy
Which AI bots are blocked (GPTBot, CCBot, ChatGPT-User, Google-Extended, Anthropic), crawl-delay settings.
Sample API response
What a single lookup returns.
{
"domain": "example-saas.com",
"scanned_at": "2026-03-28T05:00:00Z",
"tech_stack": ["Next.js", "React", "Cloudflare CDN", "GA4", "Stripe", "Intercom", "Sentry"],
"security": {
"tls_version": "1.3",
"cert_issuer": "lets-encrypt",
"hsts": true,
"csp": false,
"x_frame_options": "DENY",
"headers_present": 5,
"headers_total": 6
},
"infrastructure": {
"dns_provider": "cloudflare",
"cdn": "cloudflare",
"hosting_country": "US",
"ipv6": true,
"mx_provider": "google-workspace",
"spf": true,
"dmarc": true
},
"performance": {
"ttfb_ms": 180,
"page_size_kb": 145,
"compression": "brotli",
"http2": true,
"redirects": 1
},
"seo": {
"robots_txt": true,
"sitemap_urls": 847,
"languages": ["en", "es", "fr"],
"schema_types": ["Organization", "BreadcrumbList", "FAQPage"]
},
"ai_policy": {
"blocks_gptbot": true,
"blocks_ccbot": false,
"blocks_anthropic": false
}
}
Get API access
Available on major API marketplaces. Subscribe, get a key, start querying.
How data is collected
CrawlGraderBot scans public websites and extracts only technical metadata. No personal data. Ever.
Bot crawls
Standard HTTP GET to homepage, robots.txt, and sitemap. Respects robots.txt and crawl-delay.
Signals extracted
Headers, DNS, TLS, HTML meta, and cookie names parsed for technology and infrastructure signals.
Data served via API
Structured JSON returned to API subscribers. No public-facing reports or pages per domain.