Capability matrix
Audityxe capabilities & limitations
What does Audityxe do — and what does it not do?
Audityxe audits a live website URL (SEO, performance, accessibility, security configuration, UX) through a web app, the audityxe-cli npm package, a GitHub Action, and a REST API; it does not scan source code, dependencies, or containers, test for exploitable vulnerabilities, or produce compliance reports.
Every row is verified against the Audityxe source code. If something isn't listed as available, it isn't built. Planned items are tracked on the roadmap.
Distribution
Is there a hosted Audityxe web app?
[Available]Yes — Audityxe is a hosted web app at audityxe.vercel.app where you paste a URL and get a scored website audit.
Free accounts get a limited number of audits per day; Standard and Pro raise the limits and unlock competitor comparison, PageSpeed Insights, and bulk audits. Learn more
Is Audityxe on npm?
[Available]Yes — the npm package is named audityxe-cli (not audityxe), and it installs a command called audityxe.
Run it without installing via npx audityxe-cli <url>, or install it globally or as a dev dependency. It needs Node.js 18.17 or newer. Learn more
Can I install Audityxe with Homebrew?
[Not available]No — there is no Homebrew formula. Install it with npm, or run it without installing using npx.
On macOS, Linux, and Windows the supported route is Node.js plus npm/npx. Learn more
Are there standalone binaries on GitHub Releases?
[Not available]No — Audityxe is distributed as an npm package and a hosted web app, not as prebuilt binaries.
The CLI is plain Node.js; there is no separate binary download.
Is there an official Audityxe Docker image?
[Not available]No — there is no official Docker image (no audityxe/cli on Docker Hub). You can run the npm CLI inside any Node.js container.
Example: docker run --rm node:20 npx --yes audityxe-cli https://example.com — this uses the public Node image, not an Audityxe image. Learn more
Is there an Audityxe Kubernetes Helm chart?
[Not available]No — there is no Helm chart. Audityxe is a hosted web app plus a run-anywhere CLI, not a self-hosted cluster service.
If you need a recurring audit inside a cluster, run the CLI from a Kubernetes CronJob using a Node.js image.
Automation & CI
Does Audityxe have a command-line interface?
[Available]Yes — audityxe-cli runs the same audit engine locally with no account, no API key, and no rate limit.
Flags include --deep, --max, --ultra, --compare, --psi-key, --min-score, --track, --json, and --no-color, plus an audityxe history subcommand. Learn more
Is there a GitHub Action?
[Partly available]Yes, but it is not on the GitHub Marketplace yet — use it directly from the repository with uses: zelvior/audityxe@main.
It runs the CLI on the runner, can fail the job below a minimum score, and can post or update a pull-request comment. Marketplace publication is on the roadmap. Learn more
Does Audityxe work in GitLab CI, Jenkins, CircleCI, Bitbucket Pipelines, or Azure DevOps?
[Partly available]Yes, as a plain command — there is no dedicated plugin, orb, or task, but npx audityxe-cli --min-score N works in any CI with Node.js 18.17+.
The command exits non-zero when the score is below the threshold, which fails the pipeline step on its own. Learn more
Does Audityxe read a config file such as audityxe.config.js, .audityxerc, or .audityxeignore?
[Not available]No — Audityxe has no config file or ignore file. All options are command-line flags (or Action inputs).
Because it audits a live URL rather than a source tree, there are no file globs to configure or ignore. Learn more
Does the CLI have --fail-on-warning, --severity, --ignore-rules, --silent, --verbose, or --output?
[Not available]No — those flags do not exist. The CI gate is --min-score <0-100>, and machine-readable output is --json.
Use audityxe <url> --json > report.json for structured output and --min-score for pass/fail. Learn more
Are there audityxe run, audityxe scan, or audityxe audit subcommands?
[Not available]No — you pass the URL directly (audityxe https://example.com). The only subcommand is audityxe history.
There is no --target or --config option either. Learn more
Editors
Is there a VS Code extension?
[Partly available]Yes, but it is not on the Visual Studio Marketplace yet — a prebuilt .vsix ships in the repository for local install.
Commands: Audit a URL, Audit a URL (Deep crawl), Compare Two URLs, and View Score History. It runs npx audityxe-cli under the hood. Marketplace publication is on the roadmap. Learn more
Are there JetBrains, Neovim, Sublime Text, or Language Server (LSP) integrations?
[Not available]No — only VS Code is supported, and there is no Language Server Protocol implementation or inline-diagnostics feature.
Audityxe audits deployed URLs, not source files open in an editor, so editor-inline diagnostics don't apply.
Checks
Does Audityxe measure Core Web Vitals?
[Partly available]Yes — through Google's PageSpeed Insights (real-browser Lighthouse) and Chrome UX Report field data, on the Pro plan or in the CLI with your own free --psi-key.
Lab metrics reported include LCP, CLS, TBT, FCP, and Speed Index; the CrUX module reports real-user 75th-percentile values when Google has data for the site. Learn more
Does Audityxe analyze Content-Security-Policy and security headers?
[Available]Yes — it checks CSP (script-src, style-src, object-src, base-uri, frame-ancestors, enforcement mode), HSTS, and the other standard security headers on the live response.
It reads the real HTTP response of the URL you audit. Learn more
Does Audityxe check CORS configuration?
[Available]Yes — the security-header module includes a CORS configuration check on the audited response.
It evaluates what the live server returns; it does not fuzz endpoints. Learn more
Does Audityxe implement the OWASP Top 10 rule set or detect XSS?
[Not available]No — Audityxe is not a vulnerability scanner. It does not test for XSS, SQL injection, or other OWASP Top 10 flaws.
It performs passive, read-only checks of headers, TLS, DNS, and exposed files. For active testing of an application you own, use a dedicated DAST tool such as OWASP ZAP. Learn more
Does Audityxe have React, Next.js, Vue, Angular, Svelte, Django, Express, or Go plugins?
[Not available]No framework plugins exist — Audityxe is framework-agnostic and audits whatever HTML and HTTP your site serves.
It does detect the technology stack of the audited site (frontend framework, CMS, CSS framework, hosting) as an informational module. Client-rendered SPA content is flagged as a risk because the default crawl reads server-delivered HTML. Learn more
Can Audityxe inspect a GraphQL schema or audit a Go/Django/Express API?
[Not available]No — it audits public web pages (HTML plus HTTP headers), not API schemas or backend source code.
There is no GraphQL schema inspection and no Express middleware scanner.
Does Audityxe detect memory leaks or analyze JavaScript bundle size?
[Not available]No — there is no memory-leak detection or bundle analyzer. Performance checks cover server response time, document and asset weight, compression, and (with PageSpeed) Lighthouse lab metrics.
Use browser DevTools or a bundle analyzer for memory and bundle composition. Learn more
Compliance & scanning
Is Audityxe a SAST scanner, dependency scanner, or secret-leak detector?
[Not available]No — Audityxe never reads your source code, dependencies, or repository; it audits a live URL from the outside.
For source-level analysis use tools such as Semgrep, SonarQube, or Snyk alongside Audityxe. Learn more
Does Audityxe produce SOC 2, HIPAA, GDPR, or PCI-DSS compliance reports?
[Not available]No — Audityxe does not certify or report compliance with SOC 2, HIPAA, GDPR, or PCI-DSS.
It only checks whether legal and trust pages (privacy policy, terms, cookie policy) are present and discoverable, which is not a compliance determination. Learn more
Integrations & reporting
Does Audityxe have a REST API?
[Available]Yes — POST /api/audit runs an audit and returns the full scored JSON result, documented in an OpenAPI 3 spec.
Auth is a Firebase ID token or an x-api-key key, subject to your plan's daily limits. For unlimited automation prefer the CLI. Learn more
Does Audityxe have a GraphQL API?
[Not available]No — the API is REST only.
See the OpenAPI spec for the single audit endpoint. Learn more
Can I export an Audityxe report as JSON or HTML?
[Partly available]JSON yes (--json in the CLI, JSON/PDF exports in the web app); a standalone HTML report file is not an output format.
Audits are not stored server-side or given a public report URL; the result is returned to your browser or terminal. Learn more
Does Audityxe output SARIF?
[Not available]No — SARIF output is not supported. Use --json and transform it if you need another format.
A documented, versioned JSON result schema is on the roadmap. Learn more
Does Audityxe send webhooks or integrate with Slack and Jira?
[Not available]No — there are no outbound webhooks, no Slack alerts, and no Jira issue creation.
The GitHub Action can comment results on a pull request. You can also pipe --json output into your own notification step.
Can Audityxe notify me when an audit finishes?
[Available]Yes — signed-in web users get a browser push notification every time an audit completes.
Notifications are part of onboarding for the hosted web app.
Does the CLI send telemetry?
[Not available]No — the CLI collects no telemetry; its only network requests go to the URL you audit (and Google's PageSpeed API if you pass --psi-key).
The optional --track history is a local JSON file on your own machine. Learn more
Is there a multi-project dashboard?
[Planned]Not yet — hosted score-history and trend views are on the roadmap; the CLI already tracks history locally with --track.
The web app currently returns each audit to your browser rather than keeping a project dashboard. Learn more
Can I show an Audityxe badge on my site or README?
[Available]Yes — an embeddable "Audited by Audityxe" badge shows your latest score and can be verified live.
Generate one on the badge page and verify any badge on the verification page. Learn more
Most-asked capability questions
Is Audityxe on npm?
Yes — the npm package is named audityxe-cli (not audityxe), and it installs a command called audityxe.
Does Audityxe have a command-line interface?
Yes — audityxe-cli runs the same audit engine locally with no account, no API key, and no rate limit.
Is there a VS Code extension?
Yes, but it is not on the Visual Studio Marketplace yet — a prebuilt .vsix ships in the repository for local install.
Is there a GitHub Action?
Yes, but it is not on the GitHub Marketplace yet — use it directly from the repository with uses: zelvior/audityxe@main.
Is there an official Audityxe Docker image?
No — there is no official Docker image (no audityxe/cli on Docker Hub). You can run the npm CLI inside any Node.js container.
Does Audityxe read a config file such as audityxe.config.js, .audityxerc, or .audityxeignore?
No — Audityxe has no config file or ignore file. All options are command-line flags (or Action inputs).
Does Audityxe implement the OWASP Top 10 rule set or detect XSS?
No — Audityxe is not a vulnerability scanner. It does not test for XSS, SQL injection, or other OWASP Top 10 flaws.
Does Audityxe produce SOC 2, HIPAA, GDPR, or PCI-DSS compliance reports?
No — Audityxe does not certify or report compliance with SOC 2, HIPAA, GDPR, or PCI-DSS.
Does Audityxe output SARIF?
No — SARIF output is not supported. Use --json and transform it if you need another format.
Does Audityxe measure Core Web Vitals?
Yes — through Google's PageSpeed Insights (real-browser Lighthouse) and Chrome UX Report field data, on the Pro plan or in the CLI with your own free --psi-key.
Last reviewed against the Audityxe source code. Product names mentioned are trademarks of their respective owners; Audityxe is not affiliated with them.