| Metric | Value |
|---|---|
| Domain | qsa.sh |
| Category | Cybersecurity (External Attack Surface Management) |
| Pricing | SaaS (Freemium + Pay-per-scan) |
| Pages Crawled | 10 |
| Crawl Date | 2026-08-03 |
qsa.sh Review: Strong utility with bottlenecks (86/100) — SiteList
qsa.sh earns a 86/100, distinguishing itself through an exceptional terminal-first usability and performance profile for security engineers. However, its market growth is currently limited by a critical lack of middle-of-funnel content and technical configuration oversights.
Reviewed by SiteList Engine · 12 of 13 dimensions · published Reviewed on August 3, 2026
Is this your site?
Claim itQuick facts
- Pages Crawled
- 10
- Crawl Date
- 2026-08-03
Executive summary
The technical and on-page foundation of qsa.sh is exceptionally strong (composite score 86/100, band 'good'), characterized by clean HTML, fast performance, and an intuitive terminal-first product model. However, growth is bottlenecked by configuration oversights—such as noindexing the contact page and disabling browser caching—alongside a visible content gap in research-stage and comparison keywords. Addressing these quick wins and building entity trust will enable substantial search visibility.
Top Themes
- Technical Foundation & Caching Deficiencies: Aggressive no-store cache headers and noindexing on the contact page limit origin scaling and high-intent conversions.
- Topical & Keyword Gap: Strong transactional intent capture is undermined by a complete lack of middle-of-funnel comparison and educational glossary content.
- Entity Trust & AEO Readiness: The brand lacks explicit sameAs entity links, an llms.txt file, and open-graph completeness, hindering AI extraction.
- On-Page Optimization & Schema Polish: Core pages miss rich result opportunities due to omitted Product and FAQ structured data.
- Accessibility & Usability Friction: Minor contrast issues on muted text and focus indicator suppression create barriers for compliance.
- Overall Score
- 78.6/100
01 · First impressions & positioning — 30-second terminal scan with zero data retention
qsa.sh provides an immediate, friction-free security scan for developers by reversing the industry trend of black box tools. The site passes the five-second test by explicitly naming its open-source components like nmap and nuclei while committing to a zero-retention model. Its positioning is highly specific, targeting the active developer workflow rather than passive data collection. While it lacks traditional social proof, its transparency regarding tool versions serves as a credible proxy for trust. A minor naming inconsistency exists between the Tuxxin organization schema and the qsa.sh brand, which may cause slight friction during the payment process.
- Scan Time
- ~30 seconds
- Tool Transparency
- nuclei 3.3.9
- Naming Consistency
- Tuxxin vs qsa.sh
02 · Audience & messaging — curl-first CTA for high-sophistication security engineers
The site demonstrates a deep alignment with the security engineer's mental model by prioritizing functional utility over marketing fluff. By using curl as the primary call to action and providing detailed breakdowns of port-scanning logic, qsa.sh speaks directly to its technical audience. The messaging successfully addresses core anxieties regarding data retention and authorization, specifically through the empathetic 15-second window to press Ctrl-C safety feature. Navigation labels like Pricing and How it works are strictly functional. However, the pricing page introduces slight confusion by listing a tip option as coming soon while simultaneously offering a subscription tier.
- Primary CTA
- curl qsa.sh
- Consent UX
- 15-second window
- Pricing Clarity
- Tip option coming soon
03 · Usability — 10-second path from landing to terminal execution
Usability is exceptionally high due to a flat navigation structure and a nearly perfect information scent for its target demographic. A developer can identify the value proposition, view pricing, and execute a scan within seconds of landing. The Run it free button provides an immediate trial experience without the friction of account creation. Despite this efficiency, the mobile experience is hampered by a navigation stack that consumes significant vertical space, pushing the primary headline below the fold. Additionally, the unconventional no-account model, while technically superior for privacy, may require clearer FAQ guidance for users accustomed to traditional dashboards.
- Task Path
- Home -> Pricing
- Mobile Nav Friction
- 7 links above H1
- Account Model
- Opaque token
04 · Accessibility — 82/100 score marred by low-contrast muted text
The site features a strong technical foundation for accessibility, including functional skip links and proper semantic HTML5 landmarks. However, it fails WCAG 2.1 AA requirements for secondary information, where muted text colors lack sufficient contrast against the dark background. Interactive elements are also at risk due to the suppression of default focus outlines in the CSS, which can disorient keyboard-only users. Furthermore, the terminal simulation video lacks a text alternative or transcript, rendering the core product demonstration invisible to screen reader users. Addressing these contrast and focus-indicator issues is essential for full compliance.
- Contrast Ratio
- < 4.5:1 on muted text
- Focus Indicators
- outline: none detected
- Form Labels
- 1 missing label
05 · Design execution — 46 distinct spacing values indicate significant token drift
While the site achieves a high level of aesthetic alignment with its developer audience, the underlying design system suffers from inconsistent execution. Crawl data identified 46 distinct spacing values and 21 different font sizes, creating a subtle lack of visual rhythm across long-form pages. Mobile usability is particularly affected, with 14 tap targets on the homepage falling below the 44px minimum requirement. Additionally, the 13.6px font size used on buttons triggers browser zooming and accessibility flags on mobile devices. Standardizing these ad-hoc values into a consistent 8-step scale would significantly improve the site's professional polish.
- Spacing Tokens
- 46 distinct values
- Mobile Tap Targets
- 14 below 44px
- Button Font Size
- 13.6px
06 · Performance — 850ms LCP restricted by aggressive no-store caching
qsa.sh is a model of performance efficiency, achieving an 850ms Largest Contentful Paint by avoiding heavy images and custom web fonts. The site maintains a perfect 0.00 CLS score. However, the current configuration uses cache-control: no-store headers, which prevents browsers and CDNs from caching static marketing content. This forces a full origin request for every visit, resulting in a TTFB of 180ms—higher than expected for a Cloudflare-backed site. Moving third-party scripts from tuxxin.com to an asynchronous loading model and enabling edge caching would make the site feel instantaneous globally.
- LCP
- 850ms
- Cache Header
- no-store
07 · Writing quality — 92/100 for transparent, expert-level technical copy
The writing quality is exceptional, characterized by high specificity and the total absence of SaaS clich s. The site builds authority by citing exact tool versions, such as nuclei 3.3.9 and nmap 7.93, and openly acknowledging technical limitations like IPv6 support. This transparency resonates with the security-conscious developer audience. While the technical depth is high, the contact page exhibits high sentence-length density, averaging 37.4 words per sentence, which can hinder readability. Adding meta descriptions to the checkout pages and breaking up multi-clause instructions would further refine the professional voice and improve search result consistency.
- Sentence Density
- 37.4 words/sentence
- Technical Specificity
- naabu 2.6.1
- Meta Consistency
- Missing on /pay
08 · Decision-support surfaces — transparent pricing grid with redundant technical axes
The pricing surface is a transparent, technical grid that avoids marketing fluff and clearly differentiates between one-off scans and monthly subscriptions. However, the table includes redundant information, such as the Nmap script row, which remains identical across all tiers and adds unnecessary cognitive load. On mobile devices, the three-column layout relies on horizontal scrolling, which frequently obscures the highest-margin Deep scan option. Implementing a stacked card layout for mobile and adding a Best for... recommendation callout would better guide users through the decision-making process without requiring them to parse every technical detail.
- Redundant Axis
- Nmap script row
- Mobile UX
- Horizontal scroll
- Price Tiers
- $5/mo vs $7/scan
09 · Risk & stability — 94/100 stability with zero legacy domain baggage
The site is in a high-stability state with a 94/100 score, benefiting from its status as a new domain launched in July 2026. Crawl data confirms there are no critical indexability blockers or failed migrations, and the site is highly resilient to rendering issues because all metadata is present in the raw HTML. However, the site faces a medium exposure level to SERP erosion. Because it functions as a utility tool, it is vulnerable to 'zero-click' searches where AI Overviews might answer basic IP scanning queries. The current content is 100% concentrated on a single niche, which poses a risk during niche-specific algorithm updates. Diversifying into related security topics like CVE explainers and adding FAQ schema to the 'How it works' page will help capture more SERP real estate and hedge against these risks.
- Risk & stability score
- 94/100
- Domain age
- Launched July 2026
10 · Editorial QA of content — 91/100 for manual QA and zero detected AI-slop tells
qsa.sh demonstrates rigorous editorial discipline, earning a 91/100 for content quality. The review found zero significant AI tells, such as bilateral framing or hedge stacking, and the voice remains consistent across marketing and technical documentation. Claims are backed by specific technical references to open-source projects like Nuclei and Nmap. The 'How it works' page is a model for transparency, using FAQ schema that perfectly synchronizes with the visible content. Minor QA issues are limited to the checkout process, where both the 'Full' and 'Deep' scan pages share the same 'Checkout — qsa.sh' meta title. Differentiating these titles and implementing a 301 redirect for the /pricing/ trailing slash variant are the only required editorial polishments.
- Editorial QA score
- 91/100
- AI-slop tells
- Zero
11 · Docs & self-serve help — 58/100 score for a flat FAQ structure lacking a changelog
While the technical content is high-quality, the site earns a weak 58/100 for documentation infrastructure. Help content is currently restricted to a single 'flat' FAQ on the /how-it-works page. This lacks the formal organization expected of a security tool, such as a searchable knowledge base or a public changelog. Security-conscious users require a changelog to track updates to the scanning engine and the addition of new vulnerability templates. Furthermore, the site mentions a '10,500-template set' but provides no searchable reference for what is actually tested. Migrating the FAQ to a dedicated documentation portal and adding an /llms.txt file would improve both user self-service and AI-driven discovery of the tool's capabilities.
- Docs & help score
- 58/100
- Documentation paths found
- 0
12 · Technical SEO — 91/100 score for zero JS dependency and perfect host consolidation
The technical health of qsa.sh is exceptional, earning a 91/100. The site features perfect host consolidation and zero dependency on JavaScript for rendering, ensuring search engines can index all content immediately. Security headers are strong, utilizing TLS 1.3 and a robust Content-Security-Policy. The primary technical defects are minor configuration issues: URLs with a trailing slash, such as /pricing/, return a 200 status instead of a 301 redirect, which can split link equity. Additionally, the contact page is currently set to 'noindex', which prevents the site from ranking for branded support queries. Fixing these requires implementing a server-side redirect rule to strip trailing slashes and updating the contact page robots tag to 'index, follow'.
- Technical SEO score
- 91/100
- JS rendering dependency
- Zero
Verdict — 86/100: Strong technical utility with bottlenecks
qsa.sh is a high-performance utility that perfectly aligns with the mental model of security-conscious developers. Its primary strengths lie in its 86/100 performance score and 94/100 usability, driven by a minimal, text-heavy design that respects the user's time and technical expertise. The site successfully bypasses the 'bloated dashboard' trend by prioritizing terminal-native execution and tool transparency.
The product is currently held back by two fixable weaknesses: a critical lack of a content program (30/100) and technical configuration errors like the noindexed contact page. These issues prevent the site from capturing broader market interest beyond its immediate niche. Furthermore, the lack of middle-of-funnel comparison content makes it difficult for users to evaluate qsa.sh against established competitors.
This product is ideal for security engineers and sysadmins who prioritize terminal-native tools and transparency over complex enterprise interfaces.
- Usability Score
- 94/100
- Performance Score
- 93/100
Methodology & data notes
This review is based on a crawl of 10 pages conducted on 2026-08-03. Data sources include raw HTML analysis, performance profiling, and accessibility audits. Several dimensions were excluded due to the site's current stage: 06 (Brand mark system), 08 (Imagery & art direction), and 21 (Distribution & reach). 13 (Review-content integrity) and 31 (Programmatic SEO quality) were marked as not applicable. Enrichment is currently pending for Google Search Console data. Detailed scoring criteria can be found at /methodology.
- Data Gaps
- 5 dimensions excluded
Questions buyers actually ask
Is qsa.sh suitable for professional security audits?
Yes. The tool uses industry-standard open-source components like nmap and nuclei, providing high transparency for security engineers who need to verify the underlying scan logic.
How does qsa.sh compare to Shodan or Censys?
While Shodan and Censys offer massive global datasets, qsa.sh focuses on frictionless, terminal-native execution for specific IP scans, catering to a 'terminal-first' developer workflow.
What are the main technical limitations of the site?
The site currently suffers from aggressive no-store caching headers and a noindexed contact page, which impacts performance efficiency and high-intent user conversions.
Is the service free to use?
The business model is freemium with a pay-per-scan option. The tool is highly accessible, and pricing is transparent for the available tiers.