Skip to main content

Surface scan

What this scan can and cannot tell you

The free site scan looks at one public URL. It finds visible license signals and obvious gaps. It does not document what you ship.

Last updated: July 2, 2026

This scan checks one public URL for visible open-source license signals: Links to /license, /legal, /open-source, common third-party notice paths, and sometimes script tags on the homepage. It is a quick sanity check, not license compliance proof.

We offer it because it shows gaps before diligence tightens. The product is the maintained compliance record: Inventory from shipped inputs, reviewed licenses, full license text, publish gates. Not whatever this scan can see on your public website today.

What can this scan detect?

It answers one narrow question: Does this public URL show obvious signs of third-party license disclosure, or obvious gaps? It helps teams who have never audited their marketing site find missing links, redirects to the homepage, or empty license pages.

For SaaS vendors, the marketing site is often the first place buyers look before they ask for the real license compliance page for the shipped product.

  • HTTP responses on common license and notice paths (/license, /legal, /oss, etc.).
  • Whether those pages contain plausible license or third-party notice text, not empty shells.
  • Some third-party script URLs visible in homepage HTML.
  • Obvious redirects that send license paths to unrelated pages.
  • Missing links: No license footer, no open-source mention, no compliance URL in site map.

What can this scan not detect?

It cannot see what is not on the public page: License compliance for a shipped product lives in build inputs (lockfiles, SBOMs, release bundles), not on your homepage. A clean scan does not mean your mobile app, desktop installer, or API backend is documented.

The scan does not read transitive npm dependencies, verify SPDX identifiers, confirm full license text for each component, or know whether a human approved publish. That gap is large: Black Duck's 2025 OSSRA reports that transitive dependencies caused nearly 30% of the license conflicts it found, and none of those are visible from a homepage. It cannot replace third-party license disclosure tied to what you ship.

  • Dependencies bundled in iOS, Android, desktop, or embedded products, not on the public web.
  • Transitive packages never loaded in browser-facing JavaScript.
  • Whether listed licenses match what actually ships in the product under review.
  • Review and publish approval state: Gates, sign-offs, audit trail.
  • Copyleft compliance: Source offers, corresponding source, distribution triggers.
  • Fonts, SDKs, and icons not referenced on the scanned URL.
  • Internal-only components or air-gapped delivery models.

How does the scan differ from a license compliance page?

The scan is a teaser that finds visible gaps on a single public URL; a license compliance page is the operational record: Reviewed inventory, full license text, attribution, a stable URL for procurement, and exports aligned with releases.

Teams pass a surface scan by adding a footer link to a thin notice page. Teams pass enterprise diligence by maintaining license compliance documentation per product, updated when dependencies change.

Surface scanCompliance page
ReachOne public URL's HTML and linked pathsProduct-scoped, tied to shipped inventory
SpeedSeconds, no sign-inMaintained across releases
ReviewNo review gates or legal text verificationHuman review before publish, full license text
RoleA sanity check that finds visible gapsThe record procurement and auditors accept

What to do after you scan

If the scan finds gaps, treat that as a prompt, not a failure. Build inventory from lockfiles or SBOMs for what you actually ship. Review licenses. Publish maintained disclosure you can share in whatever format diligence asks for.

If the scan looks clean, still ask whether the visible page covers the product under contract. Marketing site license footers and product license compliance pages are often different artifacts. Both may be needed; only one satisfies a request for third-party license disclosure on the shipped product.

Next step

When you are ready to move from reading to action:

Run a free surface scan

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.