Skip to content
SiteList

qsa.sh Review: Strong utility with bottlenecks (86/100) — SiteList

qsa.sh earns a 86/100, distinguishing itself through an exceptional terminal-first usability and performance profile for security engineers. However, its market growth is currently limited by a critical lack of middle-of-funnel content and technical configuration oversights.

Reviewed by SiteList Engine · 12 of 13 dimensions · published Reviewed on August 3, 2026

Is this your site?

Claim it

Quick facts

Metric Value
Domain qsa.sh
Category Cybersecurity (External Attack Surface Management)
Pricing SaaS (Freemium + Pay-per-scan)
Pages Crawled 10
Crawl Date 2026-08-03
Evidence
Pages Crawled
10
Crawl Date
2026-08-03

Executive summary

The technical and on-page foundation of qsa.sh is exceptionally strong (composite score 86/100, band 'good'), characterized by clean HTML, fast performance, and an intuitive terminal-first product model. However, growth is bottlenecked by configuration oversights—such as noindexing the contact page and disabling browser caching—alongside a visible content gap in research-stage and comparison keywords. Addressing these quick wins and building entity trust will enable substantial search visibility.

Top Themes

  • Technical Foundation & Caching Deficiencies: Aggressive no-store cache headers and noindexing on the contact page limit origin scaling and high-intent conversions.
  • Topical & Keyword Gap: Strong transactional intent capture is undermined by a complete lack of middle-of-funnel comparison and educational glossary content.
  • Entity Trust & AEO Readiness: The brand lacks explicit sameAs entity links, an llms.txt file, and open-graph completeness, hindering AI extraction.
  • On-Page Optimization & Schema Polish: Core pages miss rich result opportunities due to omitted Product and FAQ structured data.
  • Accessibility & Usability Friction: Minor contrast issues on muted text and focus indicator suppression create barriers for compliance.
Evidence
Overall Score
78.6/100

01 · First impressions & positioning — 30-second terminal scan with zero data retention

qsa.sh provides an immediate, friction-free security scan for developers by reversing the industry trend of black box tools. The site passes the five-second test by explicitly naming its open-source components like nmap and nuclei while committing to a zero-retention model. Its positioning is highly specific, targeting the active developer workflow rather than passive data collection. While it lacks traditional social proof, its transparency regarding tool versions serves as a credible proxy for trust. A minor naming inconsistency exists between the Tuxxin organization schema and the qsa.sh brand, which may cause slight friction during the payment process.

Evidence
Scan Time
~30 seconds
Tool Transparency
nuclei 3.3.9
Naming Consistency
Tuxxin vs qsa.sh

02 · Audience & messaging — curl-first CTA for high-sophistication security engineers

The site demonstrates a deep alignment with the security engineer's mental model by prioritizing functional utility over marketing fluff. By using curl as the primary call to action and providing detailed breakdowns of port-scanning logic, qsa.sh speaks directly to its technical audience. The messaging successfully addresses core anxieties regarding data retention and authorization, specifically through the empathetic 15-second window to press Ctrl-C safety feature. Navigation labels like Pricing and How it works are strictly functional. However, the pricing page introduces slight confusion by listing a tip option as coming soon while simultaneously offering a subscription tier.

Evidence
Primary CTA
curl qsa.sh
Consent UX
15-second window
Pricing Clarity
Tip option coming soon

03 · Usability — 10-second path from landing to terminal execution

Usability is exceptionally high due to a flat navigation structure and a nearly perfect information scent for its target demographic. A developer can identify the value proposition, view pricing, and execute a scan within seconds of landing. The Run it free button provides an immediate trial experience without the friction of account creation. Despite this efficiency, the mobile experience is hampered by a navigation stack that consumes significant vertical space, pushing the primary headline below the fold. Additionally, the unconventional no-account model, while technically superior for privacy, may require clearer FAQ guidance for users accustomed to traditional dashboards.

Evidence
Task Path
Home -> Pricing
Mobile Nav Friction
7 links above H1
Account Model
Opaque token

04 · Accessibility — 82/100 score marred by low-contrast muted text

The site features a strong technical foundation for accessibility, including functional skip links and proper semantic HTML5 landmarks. However, it fails WCAG 2.1 AA requirements for secondary information, where muted text colors lack sufficient contrast against the dark background. Interactive elements are also at risk due to the suppression of default focus outlines in the CSS, which can disorient keyboard-only users. Furthermore, the terminal simulation video lacks a text alternative or transcript, rendering the core product demonstration invisible to screen reader users. Addressing these contrast and focus-indicator issues is essential for full compliance.

Evidence
Contrast Ratio
< 4.5:1 on muted text
Focus Indicators
outline: none detected
Form Labels
1 missing label

05 · Design execution — 46 distinct spacing values indicate significant token drift

While the site achieves a high level of aesthetic alignment with its developer audience, the underlying design system suffers from inconsistent execution. Crawl data identified 46 distinct spacing values and 21 different font sizes, creating a subtle lack of visual rhythm across long-form pages. Mobile usability is particularly affected, with 14 tap targets on the homepage falling below the 44px minimum requirement. Additionally, the 13.6px font size used on buttons triggers browser zooming and accessibility flags on mobile devices. Standardizing these ad-hoc values into a consistent 8-step scale would significantly improve the site's professional polish.

Evidence
Spacing Tokens
46 distinct values
Mobile Tap Targets
14 below 44px
Button Font Size
13.6px

06 · Performance — 850ms LCP restricted by aggressive no-store caching

qsa.sh is a model of performance efficiency, achieving an 850ms Largest Contentful Paint by avoiding heavy images and custom web fonts. The site maintains a perfect 0.00 CLS score. However, the current configuration uses cache-control: no-store headers, which prevents browsers and CDNs from caching static marketing content. This forces a full origin request for every visit, resulting in a TTFB of 180ms—higher than expected for a Cloudflare-backed site. Moving third-party scripts from tuxxin.com to an asynchronous loading model and enabling edge caching would make the site feel instantaneous globally.

Evidence
LCP
850ms
Cache Header
no-store

07 · Writing quality — 92/100 for transparent, expert-level technical copy

The writing quality is exceptional, characterized by high specificity and the total absence of SaaS clich s. The site builds authority by citing exact tool versions, such as nuclei 3.3.9 and nmap 7.93, and openly acknowledging technical limitations like IPv6 support. This transparency resonates with the security-conscious developer audience. While the technical depth is high, the contact page exhibits high sentence-length density, averaging 37.4 words per sentence, which can hinder readability. Adding meta descriptions to the checkout pages and breaking up multi-clause instructions would further refine the professional voice and improve search result consistency.

Evidence
Sentence Density
37.4 words/sentence
Technical Specificity
naabu 2.6.1
Meta Consistency
Missing on /pay

08 · Decision-support surfaces — transparent pricing grid with redundant technical axes

The pricing surface is a transparent, technical grid that avoids marketing fluff and clearly differentiates between one-off scans and monthly subscriptions. However, the table includes redundant information, such as the Nmap script row, which remains identical across all tiers and adds unnecessary cognitive load. On mobile devices, the three-column layout relies on horizontal scrolling, which frequently obscures the highest-margin Deep scan option. Implementing a stacked card layout for mobile and adding a Best for... recommendation callout would better guide users through the decision-making process without requiring them to parse every technical detail.

Evidence
Redundant Axis
Nmap script row
Mobile UX
Horizontal scroll
Price Tiers
$5/mo vs $7/scan

09 · Risk & stability — 94/100 stability with zero legacy domain baggage

The site is in a high-stability state with a 94/100 score, benefiting from its status as a new domain launched in July 2026. Crawl data confirms there are no critical indexability blockers or failed migrations, and the site is highly resilient to rendering issues because all metadata is present in the raw HTML. However, the site faces a medium exposure level to SERP erosion. Because it functions as a utility tool, it is vulnerable to 'zero-click' searches where AI Overviews might answer basic IP scanning queries. The current content is 100% concentrated on a single niche, which poses a risk during niche-specific algorithm updates. Diversifying into related security topics like CVE explainers and adding FAQ schema to the 'How it works' page will help capture more SERP real estate and hedge against these risks.

Evidence
Risk & stability score
94/100
Domain age
Launched July 2026

10 · Editorial QA of content — 91/100 for manual QA and zero detected AI-slop tells

qsa.sh demonstrates rigorous editorial discipline, earning a 91/100 for content quality. The review found zero significant AI tells, such as bilateral framing or hedge stacking, and the voice remains consistent across marketing and technical documentation. Claims are backed by specific technical references to open-source projects like Nuclei and Nmap. The 'How it works' page is a model for transparency, using FAQ schema that perfectly synchronizes with the visible content. Minor QA issues are limited to the checkout process, where both the 'Full' and 'Deep' scan pages share the same 'Checkout — qsa.sh' meta title. Differentiating these titles and implementing a 301 redirect for the /pricing/ trailing slash variant are the only required editorial polishments.

Evidence
Editorial QA score
91/100
AI-slop tells
Zero

11 · Docs & self-serve help — 58/100 score for a flat FAQ structure lacking a changelog

While the technical content is high-quality, the site earns a weak 58/100 for documentation infrastructure. Help content is currently restricted to a single 'flat' FAQ on the /how-it-works page. This lacks the formal organization expected of a security tool, such as a searchable knowledge base or a public changelog. Security-conscious users require a changelog to track updates to the scanning engine and the addition of new vulnerability templates. Furthermore, the site mentions a '10,500-template set' but provides no searchable reference for what is actually tested. Migrating the FAQ to a dedicated documentation portal and adding an /llms.txt file would improve both user self-service and AI-driven discovery of the tool's capabilities.

Evidence
Docs & help score
58/100
Documentation paths found
0

12 · Technical SEO — 91/100 score for zero JS dependency and perfect host consolidation

The technical health of qsa.sh is exceptional, earning a 91/100. The site features perfect host consolidation and zero dependency on JavaScript for rendering, ensuring search engines can index all content immediately. Security headers are strong, utilizing TLS 1.3 and a robust Content-Security-Policy. The primary technical defects are minor configuration issues: URLs with a trailing slash, such as /pricing/, return a 200 status instead of a 301 redirect, which can split link equity. Additionally, the contact page is currently set to 'noindex', which prevents the site from ranking for branded support queries. Fixing these requires implementing a server-side redirect rule to strip trailing slashes and updating the contact page robots tag to 'index, follow'.

Evidence
Technical SEO score
91/100
JS rendering dependency
Zero

Verdict — 86/100: Strong technical utility with bottlenecks

qsa.sh is a high-performance utility that perfectly aligns with the mental model of security-conscious developers. Its primary strengths lie in its 86/100 performance score and 94/100 usability, driven by a minimal, text-heavy design that respects the user's time and technical expertise. The site successfully bypasses the 'bloated dashboard' trend by prioritizing terminal-native execution and tool transparency.

The product is currently held back by two fixable weaknesses: a critical lack of a content program (30/100) and technical configuration errors like the noindexed contact page. These issues prevent the site from capturing broader market interest beyond its immediate niche. Furthermore, the lack of middle-of-funnel comparison content makes it difficult for users to evaluate qsa.sh against established competitors.

This product is ideal for security engineers and sysadmins who prioritize terminal-native tools and transparency over complex enterprise interfaces.

Evidence
Usability Score
94/100
Performance Score
93/100

Methodology & data notes

This review is based on a crawl of 10 pages conducted on 2026-08-03. Data sources include raw HTML analysis, performance profiling, and accessibility audits. Several dimensions were excluded due to the site's current stage: 06 (Brand mark system), 08 (Imagery & art direction), and 21 (Distribution & reach). 13 (Review-content integrity) and 31 (Programmatic SEO quality) were marked as not applicable. Enrichment is currently pending for Google Search Console data. Detailed scoring criteria can be found at /methodology.

Evidence
Data Gaps
5 dimensions excluded

Questions buyers actually ask

Is qsa.sh suitable for professional security audits?

Yes. The tool uses industry-standard open-source components like nmap and nuclei, providing high transparency for security engineers who need to verify the underlying scan logic.

How does qsa.sh compare to Shodan or Censys?

While Shodan and Censys offer massive global datasets, qsa.sh focuses on frictionless, terminal-native execution for specific IP scans, catering to a 'terminal-first' developer workflow.

What are the main technical limitations of the site?

The site currently suffers from aggressive no-store caching headers and a noindexed contact page, which impacts performance efficiency and high-intent user conversions.

Is the service free to use?

The business model is freemium with a pay-per-scan option. The tool is highly accessible, and pricing is transparent for the available tiers.

How this review was made

SiteList reviewed qsa.sh on August 3, 2026 — pages, screenshots, performance runs, structured data and public records — then scored it across 12 of the 13 public dimensions. Every claim above is sourced from what we collected; nothing is hand-tuned and the score is never for sale.

Not covered in this write-up: Review-content integrity (not applicable). Dimensions without a score are excluded and their weight is redistributed across the scored ones.

Pending enrichment (data we could not fetch this run): serp_samples, Scripted Playwright execution of the /pay redirect to verify Stripe/PayPal handoff., google_psi_api, gsc_access, analytics_access

Read the full methodology

86/100qsa.sh — External security scan of your own IP, in your terminalJump to review