Primary scan status
primary_scan_status
Optional
Outcome of GSA's main page scan: completed, timeout, dns_resolution_error, connection_reset, ssl_version_cipher_mismatch and 15 other codes. Backs uswds, dap and viewport_meta_tag.
Federal Website Compliance Auditor — GSA Site Scanning API
Pricing
from $2.75 / 1,000 results
Audit 29,000+ federal .gov websites via the GSA Site Scanning API. Per-agency compliance scorecards (USWDS, DAP, HTTPS/HSTS, IPv6, mobile, required links, Section 508), flat site exports and gap lists of sites missing a technology — with explicit coverage and per-scan status on every row.
Pricing
from $2.75 / 1,000 results
Rating
0.0
(0)
Developer
Kyle Maloney
Maintained by CommunityActor stats
0
Bookmarked
1
Total users
0
Monthly active users
8 days ago
Last modified
Share
Row type
row_type
Optional
Kind of row: 'agency_scorecard' (scorecard mode), 'site' (sites mode) or 'gap' (gaps mode).
Source
source
Optional
Upstream data source for this row. Always 'GSA Site Scanning API v1'.
Scope
scope
Optional
The scope this row was measured within: the exact GSA agency name queried, or 'ALL AGENCIES (national sweep)'.
Requested agency
requested_agency
Optional
The agency string you supplied in the input, before name resolution. Null on a national sweep.
Name resolution
agency_name_resolution
Optional
How your agency string was matched to GSA's exact, case-sensitive filter: exact, alias, case_insensitive, unique_substring, ambiguous, no_match, or national_sweep.
Query status
api_query_status
Optional
Per-scope outcome. 'ok' = the whole scope was fetched. 'partial' = only part of it was (see coverage_pct). 'no_match' = your agency name matched no GSA agency and NOTHING was measured. 'unavailable' = the API did not answer for this scope. Never treat anything but 'ok' as a complete answer.
Source error
source_error
Optional
The upstream error for this scope, when there was one. Null on a healthy run — that is good news, not a missing value.
Sites available
sites_available
Optional
How many sites GSA catalogues in this scope (the API's own meta.totalItems). The truncation guard.
Sites fetched
sites_fetched
Optional
How many of those sites this run actually retrieved.
Coverage %
coverage_pct
Optional
sites_fetched as a percentage of sites_available. Below 100 means every percentage and score on this row describes a subset, not the scope.
Complete
is_complete
Optional
True only when the entire scope was retrieved. Null when coverage could not be determined.
Completeness note
data_completeness_note
Optional
Plain-English explanation whenever this row does NOT describe a complete, successfully measured scope. Null on a complete run.
Sites analyzable
sites_analyzable
Optional
Fetched sites that survived the live/filter gates and the input filters — the population the rows on this scope were built from.
Agency
agency
Optional
Federal agency that owns the website(s).
Bureau
bureau
Optional
Sub-agency / bureau owner (site & gap rows).
Branch
branch
Optional
Government branch. Four values exist upstream: Executive, Legislative, Judicial and Federal.
Domain
domain
Optional
Website domain (site & gap rows).
URL
url
Optional
Resolved site URL.
Base domain
base_domain
Optional
Registered base domain.
Initial base domain
initial_base_domain
Optional
Base domain of the URL GSA started the scan from, before redirects.
TLD
top_level_domain
Optional
Top-level domain of the resolved site (gov, mil, edu, com).
Live
live
Optional
True if the site responded to the scan.
HTTP status
status_code
Optional
HTTP status code from the primary scan.
Redirected
redirect
Optional
True if the initial URL redirected elsewhere. Null if not scanned.
Media type
media_type
Optional
Content-Type of the scanned response. Almost always text/html; anything else usually means the record is an API or asset endpoint, not a website.
Canonical link
canonical_link
Optional
rel=canonical URL declared by the page, when present.
Page title
page_title
Optional
The scanned page's .
Meta description
page_description
Optional
The scanned page's meta description.
Language
language
Optional
Declared page language (en, en-US, es).
CMS
cms
Optional
Detected content management system. Null on 69% of live sites — GSA only fingerprints a handful of platforms.
Hosting provider
cloud_provider
Optional
Detected hosting/cloud provider hostname (cloud.gov, amazonaws.com, cloudfront.net, akamaitechnologies.com). Null on 59% of live sites where GSA could not attribute the host.
Front-end tooling
tooling
Optional
JavaScript libraries/frameworks GSA detected (jquery, bootstrap, react, vue, angular, htmx, tailwind). Null when not scanned.
Source lists
source_list
Optional
Which federal website inventories this domain appears in (omb_idea, pulse, dap2, public_inventory, final_url_websites).
USWDS
uswds
Optional
True if the US Web Design System was detected (usa- classes present, or the cumulative USWDS score >= 50). Null if the page was not scanned.
USWDS score
uswds_count
Optional
Raw cumulative USWDS detection score from the scan.
USWDS usa- class score
uswds_usa_classes
Optional
GSA's weighted score for usa- prefixed CSS classes on the page (0 to 110+ in steps of 5).
USWDS version score
uswds_version
Optional
GSA's numeric USWDS version signal.
USWDS semantic version
uswds_semantic_version
Optional
Exact USWDS release detected, when the site publishes one. Populated on ~27% of live sites.
Public Sans score
uswds_publicsans_font
Optional
Detection score for the official Public Sans typeface.
<main> landmark
main_element_present
Optional
True if the page exposes a
landmark — a baseline Section 508 / WCAG structural requirement.DAP
dap
Optional
True if the Digital Analytics Program tag was detected.
DAP version
dap_version
Optional
Detected DAP script version.
DAP agency parameter
dap_agency_parameter
Optional
The agency code the site passes to DAP — reveals mis-tagged sites reporting under the wrong agency.
GA4 tag ID
ga_tag_id
Optional
Google Analytics 4 measurement ID found on the page.
HTTPS enforced
https_enforced
Optional
True if HTTP requests are redirected to HTTPS. NULL means the security scan did not complete (18.8% of live federal sites) — it does NOT mean HTTPS is unenforced. Check security_scan_status.
HSTS
hsts
Optional
True if HTTP Strict Transport Security is enabled. Null when the security scan did not complete.
IPv6
ipv6
Optional
True if the domain has IPv6 (AAAA) support.
Mobile viewport
viewport_meta_tag
Optional
True if a mobile viewport meta tag is present.
Sitemap.xml
sitemap_xml_detected
Optional
True if a sitemap.xml was found.
Robots.txt
robots_txt_detected
Optional
True if a robots.txt was found.
Failed pillars
failed_pillars
Optional
Compliance pillars this site measurably FAILS. A pillar that was never measured is not listed here — see pillars_unmeasured.
Pillars measured
pillars_measured
Optional
Which of the 8 pillars GSA actually measured on this site.
Pillars NOT measured
pillars_unmeasured
Optional
Pillars with no measurement on this site — the answer is unknown, not negative.
Primary scan status
primary_scan_status
Optional
Outcome of GSA's main page scan: completed, timeout, dns_resolution_error, connection_reset, ssl_version_cipher_mismatch and 15 other codes. Backs uswds, dap and viewport_meta_tag.
DNS scan status
dns_scan_status
Optional
Outcome of the DNS scan. Backs the ipv6 pillar.
Security scan status
security_scan_status
Optional
Outcome of the HTTPS/HSTS scan. 'unknown_error' on 18.8% of live sites, which is exactly why https_enforced and hsts can be null.
Robots.txt scan status
robots_txt_scan_status
Optional
Outcome of the robots.txt fetch. Backs the robots_txt pillar.
Sitemap scan status
sitemap_xml_scan_status
Optional
Outcome of the sitemap.xml fetch. Backs the sitemap_xml pillar.
Accessibility scan status
accessibility_scan_status
Optional
Outcome of the axe-core accessibility scan. Backs accessibility_violations_total.
Performance scan status
performance_scan_status
Optional
Outcome of the Core Web Vitals scan. Backs largest_contentful_paint_ms and cumulative_layout_shift.
www scan status
www_scan_status
Optional
404 scan status
not_found_scan_status
Optional
Outcome of the custom-404 probe. Backs not_found_test_passed.
Required links found
required_links_found
Optional
Which of the 9 federally required footer links (about, accessibility, privacy, foia, no_fear_act, inspector_general, usa_gov, vulnerability_disclosure, budget_performance) were detected. NULL means GSA did not scan links on this site — not that none are present.
Required links missing
required_links_missing
Optional
Required footer links NOT detected. Null when link scanning did not run on this site (33% of live sites).
Required links %
required_links_pct
Optional
Percent of the 9 required links detected. On scorecard rows this is the agency mean over sites where links were scanned.
Required links measured
required_links_measured
Optional
Scorecard rows: how many of the agency's sites had their footer links scanned at all.
Accessibility violations
accessibility_violations_total
Optional
Total axe-core accessibility violations found. Null when the accessibility scan did not complete — NOT zero.
Violation breakdown
accessibility_violations_detail
Optional
JSON breakdown by rule family (contrast, images, aria, link-purpose, lists, page-titled, form-names, keyboard-access).
LCP (ms)
largest_contentful_paint_ms
Optional
Largest Contentful Paint in milliseconds. Null when the performance scan did not complete.
CLS
cumulative_layout_shift
Optional
Cumulative Layout Shift score. Null when the performance scan did not complete.
3rd-party services
third_party_service_count
Optional
Count of distinct third-party service domains loaded by the site.
3rd-party domains
third_party_service_domains
Optional
The actual third-party domains loaded — a privacy and supply-chain signal.
Outbound domains
hyperlink_domain_count
Optional
Number of distinct domains the page links out to.
Login provider
login_provider
Optional
Detected identity provider (login.gov, id.me, okta, secureauth). Populated on ~8% of live sites.
Login evidence
login_form_evidence
Optional
The literal markup snippet that indicated a login form, when one was found.
Site search
site_search
Optional
True if on-site search was detected.
Search.gov
search_dot_gov
Optional
True if the site uses the federal Search.gov service. Upstream emits true or null only — a null means not detected, never a verified 'no'.
Robots.txt URL
robots_txt_url
Optional
URL of the robots.txt GSA fetched.
Robots.txt status
robots_txt_status_code
Optional
HTTP status returned for robots.txt.
Crawl-delay
robots_txt_crawl_delay
Optional
Crawl-delay directive in robots.txt, when declared.
Sitemaps in robots.txt
robots_txt_sitemap_locations
Optional
Sitemap URLs advertised inside robots.txt.
Sitemap URL
sitemap_xml_url
Optional
URL of the sitemap.xml GSA fetched.
Sitemap status
sitemap_xml_status_code
Optional
HTTP status returned for sitemap.xml.
Sitemap URL count
sitemap_xml_count
Optional
Number of URLs listed in the sitemap — a crude site-size proxy.
Sitemap PDF count
sitemap_xml_pdf_count
Optional
Number of PDFs listed in the sitemap — a Section 508 remediation signal.
Sitemap lastmod
sitemap_xml_lastmod
Optional
Most recent lastmod date in the sitemap — a content-freshness signal.
www URL
www_url
Optional
www status
www_status_code
Optional
HTTP status of the www variant.
www matches apex
www_same
Optional
True if the www variant serves the same content as the apex domain. Null when the www scan did not run.
404 handled
not_found_test_passed
Optional
True if the site returns a proper 404 for a missing page. Null when the probe did not run.
Pageviews
pageviews
Optional
Recent DAP pageviews (traffic signal for lead prioritization). Null when the site is not in DAP.
Visits
visits
Optional
Recent DAP visits. Null when the site is not in DAP.
Scan date
scan_date
Optional
Timestamp of the underlying GSA scan. On scorecard rows, the newest scan in the agency group.
Gap pillar
pillar
Optional
The pillar this gap row fails (gaps mode).
Total sites
total_sites
Optional
Live scanned sites counted for this agency (scorecard rows). Compare with sites_available to see whether the whole agency was covered.
USWDS %
uswds_pct
Optional
Percent of the agency's MEASURED sites using USWDS.
USWDS measured
uswds_measured
Optional
How many of the agency's sites this percentage was computed over.
DAP %
dap_pct
Optional
Percent with the DAP analytics tag.
DAP measured
dap_measured
Optional
Denominator behind dap_pct.
HTTPS %
https_enforced_pct
Optional
Percent enforcing HTTPS.
HTTPS measured
https_enforced_measured
Optional
Denominator behind https_enforced_pct. Typically lower than total_sites: GSA's security scan fails on ~19% of live federal sites.
HSTS %
hsts_pct
Optional
Percent with HSTS enabled.
HSTS measured
hsts_measured
Optional
Denominator behind hsts_pct.
IPv6 %
ipv6_pct
Optional
Percent with IPv6 support.
IPv6 measured
ipv6_measured
Optional
Denominator behind ipv6_pct.
Mobile %
viewport_meta_tag_pct
Optional
Percent with a mobile viewport tag.
Mobile measured
viewport_meta_tag_measured
Optional
Denominator behind viewport_meta_tag_pct.
Sitemap %
sitemap_xml_pct
Optional
Percent with a sitemap.xml.
Sitemap measured
sitemap_xml_measured
Optional
Denominator behind sitemap_xml_pct.
Robots %
robots_txt_pct
Optional
Percent with a robots.txt.
Robots measured
robots_txt_measured
Optional
Denominator behind robots_txt_pct.
Compliance score
compliance_score
Optional
Composite 0-100 score: mean of the agency's per-pillar percentages. Read it together with coverage_pct and is_complete — on a partial scope it describes the subset only.
Worst offenders
worst_offenders
Optional
Up to 5 agency domains failing the most pillars, formatted 'domain (n fails)'.
Pillars fully measured
pillars_fully_measured
Optional
How many of the 8 pillars were measured on every single site in the group. Below 8 means at least one percentage rests on a smaller denominator than total_sites.
Sites with a gap
sites_missing_a_measurement
Optional
Sites in the group where at least one pillar could not be measured.
Sites with scan errors
scan_errors
Optional
Sites in the group where at least one of GSA's nine sub-scans did not complete.
Accessibility clean %
accessibility_clean_pct
Optional
Percent of scanned sites with zero axe-core violations.
Accessibility measured
accessibility_measured
Optional
Sites in the group with a completed accessibility scan.