Bounded public crawl
The scanner fetches the submitted public HTTP/HTTPS page and up to 12 same-host internal HTML pages. Redirects, response size and time are capped.
SSRF protection
Localhost, private/reserved IP ranges, non-web protocols and non-standard ports are rejected. DNS is validated and the selected public IP is pinned for each outbound request.
Deterministic scores
Enabled categories start at 100. Critical, high, medium and low findings apply fixed deductions. Informational observations do not reduce a category score.
No fake AI rankings
Static crawling can measure access, structure, evidence, entities, citations and technical readiness. It cannot truthfully claim a current ChatGPT, Gemini, Perplexity or Google AI position without direct observation of those systems.
Current crawler distinction
OpenAI currently documents OAI-SearchBot for search discovery and GPTBot separately for model-training crawling. The checker therefore evaluates them separately rather than treating GPTBot as the search bot.
Privacy
Scan reports are kept only in the visitor session for export. GeoAIRanking does not require an account and does not intentionally store crawled page content in a database.