Know When the Website Breaks After Launch

MetricPoints watches the signals that keep a site reachable, protected, findable, delivering, working, and recoverable, then shows a clear health summary with developer-grade evidence underneath.

Run a Free Site Check

Check visible security gaps first, then add continuous monitoring for the problems that happen later. No signup requiredInstant results

CSP Policy Builder

FREE

Generate a starter Content Security Policy when you are ready to control what the browser can load.

Try Content Security Policy (CSP) Builder →

Security Headers Checker

FREE

Analyze CSP, HSTS, clickjacking, MIME sniffing, referrer privacy, browser permissions, and legacy XSS header posture instantly.

Check Headers →

Free tools show a snapshot. Paid monitoring tells you when headers, DNS, domains, indexability, browser health, forms, assets, or protection signals change after that snapshot.

Why Always-On Website Monitoring Matters

For Website Owners

  • Protect Your Reputation - Catch broken experiences, hidden drift, and weakened trust signals before customers lose confidence
  • Keep Users Safe - Watch for risky scripts, weakened headers, policy violations, and suspicious DNS or asset changes
  • Stay Findable and Reachable - Keep robots, sitemaps, canonicals, domains, SSL, and DNS in view before quiet setup mistakes hurt the site
  • Know What to Do Next - Turn health checks into plain-language impact, incident history, and recommended action

For Developers, Consultants, and Agencies

  • Client Trust - Proactive monitoring helps you find issues before a client has to tell you something is wrong
  • Care Plan Proof - Offer plain-language health reports across uptime, DNS, indexability, forms, email, browser health, and protection
  • Better Coverage - Watch the site setup, browser-side, and protection issues hosting tools miss
  • Fewer Surprise Calls - Catch quiet issues before they become customer or client problems

Website Health

Watch availability, SSL, domains, DNS, redirects, indexability, sitemaps, forms, email health, assets, and backups in one place.

Compare Health Plans

Protection Monitoring

Watch CSP violations, risky resource loads, security header drift, DNS integrity, CMS exposure, and privacy smoke signals.

Compare Coverage Plans

Developer Diagnostics

Open a browser error, jump to the related session context and replay, then use the stack, console, performance, and CSP evidence to fix the right thing.

Compare Diagnostic Access

What MetricPoints Keeps Healthy

Your website is more than a page that loads. MetricPoints watches the setup, security, discoverability, delivery, browser, and recovery signals that quietly decide whether the site keeps doing its job.

Reachable

Uptime, SSL expiry, domain registration, DNS drift, DNS integrity, canonical redirects, CDN and cache behavior.

Protected

CSP report capture, managed CSP versions, security header drift, risky scripts, DNS integrity, CMS exposure, and privacy smoke checks.

Findable

Robots.txt, noindex signals, sitemaps, stale lastmod data, canonicals, redirects, AI crawler policy, and llms.txt.

Delivering

MX, SPF, DKIM, DMARC, BIMI, contact-form delivery, CRM or webhook proof, and tracking installs.

Working

Browser errors, error-to-replay context, performance sessions, synthetic flows, broken assets, mixed content, and analytics tags.

Accountable

Backup evidence, restore-test age, incidents, site incident alerts, findings, service windows, access blockers, health reports, and recommended next steps.

All Functions and Checks Performed

These are the concrete checks, collectors, and follow-up functions MetricPoints currently exposes across unified site monitoring, developer diagnostics, managed CSP, and the free tools.

Availability and Routing

  • Uptime checks with expected status ranges
  • SSL certificate expiry checks
  • Domain registration and auto-renew evidence
  • Canonical redirect checks
  • Redirect-chain length checks
  • Synthetic user-flow checks

DNS and Email

  • DNS drift baseline comparison
  • A, AAAA, CNAME, NS, MX, CAA, and DS record review
  • DNSSEC, TTL anomaly, wildcard DNS, dangling CNAME, and resolver disagreement checks
  • Suspicious DNS change detection
  • Email MX, SPF, DKIM, DMARC, and optional BIMI checks

Indexability and AI Discovery

  • Robots.txt availability and allow/block posture
  • Noindex detection on important paths
  • Sitemap health and sample URL checks
  • Stale sitemap lastmod checks
  • AI crawler policy monitoring
  • llms.txt presence and freshness checks

Browser Protection

  • CSP violation intake and grouping
  • Managed CSP policy versions and rollback history
  • Policy recommendations from real violation context
  • Security header drift monitoring
  • CSP reporting requirement checks
  • Referrer-Policy, Permissions-Policy, and cross-origin isolation review

Free Security Header Analyzer

  • Content-Security-Policy and CSP-Report-Only analysis
  • Strict-Transport-Security max-age, includeSubDomains, and preload analysis
  • X-Frame-Options clickjacking analysis
  • X-Content-Type-Options nosniff analysis
  • Referrer-Policy privacy analysis
  • Permissions-Policy browser feature analysis
  • X-XSS-Protection legacy-header review

Visitor Experience

  • Browser beacon installation checks
  • JavaScript error intake
  • Automatic error grouping
  • Source-mapped stack traces
  • Breadcrumbs, console logs, session context, and replay allowance
  • Performance sessions and bottleneck recommendations

Conversion and Site Setup

  • Form delivery health checks
  • Monitored form configuration
  • Analytics and tracking install checks
  • Google Analytics, Google Tag Manager, Plausible, Fathom, Matomo, Meta Pixel, Microsoft Clarity, Hotjar, Segment, and PostHog detection
  • Asset integrity checks for scripts, styles, images, and fonts
  • Optional external asset and SRI review

Operations and Reporting

  • Incident creation and correlation
  • Site incident alert routing
  • Findings and recommendation logs
  • Service windows
  • Access blockers
  • Backup and restore evidence checks
  • Email, Slack, webhook, and WordPress alert delivery
  • Client-safe service reports and share links
  • Usage reconciliation and activation checklists

JavaScript Event Tracking

What it catches

Browser error tracking captures runtime failures in the browser. Those failures can stop forms, carts, menus, search, logins, dashboards, and other customer-facing workflows even when the server is healthy.

Common problems
  • Broken forms - Leads or support messages never submit
  • Checkout issues - Cart or payment steps fail for some visitors
  • Plugin conflicts - WordPress updates break browser behavior
  • API and resource failures - Frontend features cannot load what they need
Why monitor events?
  • Fix before complaints - Know what broke without waiting on user or client reports
  • Prioritize impact - Group repeated failures instead of chasing one-off noise
  • Protect revenue - Catch broken conversion paths faster
  • Reduce support load - Give teams the context they need to reproduce issues

Best fit

E-commerce Sites

Prevent cart abandonment caused by browser errors in checkout and product flows.

Business Websites

Keep forms, calendars, quote requests, and key calls to action working.

Web Applications

Find production regressions that did not appear in development or staging.

Client Websites

Give clients proactive monitoring as part of an ongoing care plan.

Key features

  • ✔️ Real-time error collection - Capture browser failures as they occur
  • ✔️ Automatic grouping - Organize repeated events for faster triage
  • ✔️ Source-map support - Read production stack traces more clearly
  • ✔️ Error-to-replay context - Open an error and jump directly to the session, breadcrumbs, console logs, and activity around it
  • ✔️ Performance sessions - Correlate browser errors with load timing, memory, CPU, and bottleneck recommendations
  • ✔️ Alerts via email, Slack, and webhooks - Notify the right people quickly
  • ✔️ WordPress plugin integration Available Now!
Explore Full Coverage
WordPress Integration

Get our WordPress plugin for browser monitoring and optional CSP monitoring.

WordPress Plugin Details

CSP and Security Header Monitoring

What is Content Security Policy (CSP)?

Content Security Policy is a browser protection layer that helps control which scripts, images, styles, frames, and other resources your site can load. Monitoring it helps you understand attacks, risky third-party behavior, and policy changes over time.

What CSP helps prevent
  • Cross-site scripting - Malicious scripts injected into pages
  • Rogue resources - Unexpected scripts, images, frames, or styles
  • Data injection - Unauthorized content from untrusted sources
  • Policy drift - Protection weakening after site or vendor changes
Why monitor CSP and headers?
  • Detect suspicious activity - See blocked or unexpected resource loads
  • Avoid broken protection - Know when headers disappear or change
  • Tune safely - Learn what a policy would block before tightening it
  • Support audits - Keep historical visibility into security coverage

Best fit

E-commerce Sites

Protect payment forms and third-party scripts from unexpected browser-side risk.

Business Websites

Maintain trust by monitoring security headers and risky resource changes.

Web Applications

Secure user interactions by limiting and monitoring what can execute in the browser.

Client Websites

Offer ongoing protection monitoring as a premium agency service.

Key features

  • ✔️ Real-time CSP report capture - Collect violation reports from production
  • ✔️ Managed CSP workflow - Keep policy behavior managed from MetricPoints with policy history and rollback
  • ✔️ Headers history and monitoring - Track HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, CSP, and CSP-Report-Only over time
  • ✔️ Alerts via email, Slack, and webhooks - Stay informed of important security changes
  • ✔️ Retention and exportable logs - Support compliance and review needs
  • ✔️ Policy recommendations - Improve CSP rules with real violation context
  • ✔️ WordPress plugin integration Available Now!
Explore Complete Coverage
WordPress Integration

Use the same WordPress plugin to enable CSP reporting and header monitoring.

WordPress Plugin Details

Complete Website Health Coverage

A site can fail quietly in several ways: it can go unreachable, stop delivering leads, lose search or AI discoverability, weaken its protection, drift from the setup you intended, or break for real visitors.

Website Health Monitoring

Shows what is drifting or becoming unhealthy:

  • Monitors setup signals such as uptime, domains, DNS, DNS integrity, SSL, robots, sitemaps, AI crawler policy, llms.txt, and redirects
  • Checks delivery paths including forms, email domain health, analytics installs, key assets, and synthetic flows
  • Summarizes impact so owners know what needs attention
  • Preserves history for health reports and follow-up

Protection and Diagnostics

Shows what is becoming risky or broken:

  • Monitors policy violations from production traffic and turns them into CSP recommendations
  • Tracks header drift when CSP, HSTS, clickjacking, MIME, referrer, permissions, or cross-origin protections change
  • Surfaces browser failures that affect forms, checkout, dashboards, and user flows, with source maps, breadcrumbs, replay, and performance context
  • Supports audits and fixes with historical visibility, incidents, findings, recommendations, exports, and developer evidence

Real-World Benefits of Complete Health Monitoring

E-commerce Websites

Catch broken carts, risky scripts, domain or DNS drift, checkout form delivery problems, and protection changes around payment flows.

Business Websites

Keep lead forms, email domain health, indexability, security headers, performance, and visitor trust under watch.

Web Agencies

Offer ongoing monitoring as a care-plan upgrade clients can understand: fewer silent failures, clearer protection, better health reports.

Product Teams

Give engineers, support, and operations a shared view of health drift, real browser failures, and security evidence.