What we check
The five surfaces of your money page, watched every day.
Roughly 30 checks, grouped by what they protect, not padded into a longer list. Here is exactly what CopyMosaic looks for on each scan, the depth behind each line (8 secret formats, 13 analytics and ad tags, every UTM and click ID), and the things we deliberately do not check.
5surfaces
~30checks
8secret formats
10analytics tools
dailyre-scan
016 checkout processors watched
Money path
Can a visitor still pay you. The break nothing on your end throws an error for.
Broken buy & signup links
We follow every checkout, subscribe, and get-started link (Stripe Checkout, buy.stripe.com, Gumroad, PayPal, Lemon Squeezy, Paddle, plus path-based money URLs), through up to 3 redirects, and flag any that 404, error, or go unreachable.
CTA copy drift
Your main button text (“Start free trial”) is compared to the value you set. We flag it when the button changes wording or disappears after a deploy.
Offer & price drift
The prices rendered on the page are compared to your expected offer. We flag it when the number on the page stops matching the number in your ads.
Placeholder & staging copy
“Coming soon”, “lorem ipsum”, “under construction”, “staging” and 5 more dead-giveaways. Critical when they land in your title, headline, or a button.
028 params · 13 analytics & ad tags
Attribution
Does your tracking survive the click. The leak that turns paid traffic into a quiet week.
Attribution params preserved
utm_*, gclid, fbclid, ttclid, li_fat_id, ref, affiliate, aff. We walk your redirect chain and flag any param dropped before the final URL. The paid click IDs (gclid, fbclid, ttclid, li_fat_id) escalate to critical, that is ad spend you can no longer attribute.
Analytics and ad tags present
GA4, Google Tag Manager, Google Ads conversion tags, Meta Pixel, TikTok Pixel, LinkedIn Insight Tag, PostHog, Plausible, Fathom, Mixpanel, Segment, Hotjar, FullStory. We record which ones appear in the page a logged-out visitor loads, so the daily monitor catches one that silently drops after a redeploy. Consent-gated tags may still need manual confirmation.
038 secret-key formats
Trust & secrets
Nothing embarrassing shipped into the browser where anyone can read it.
Live secret keys in page source
Stripe live & restricted keys, AWS access key IDs, GitHub personal tokens, OpenAI keys (including project / service keys), and raw private-key blocks, scanned across your public HTML and JS. Eight formats, redacted in the report.
Test keys shipped to production
sk_test / rk_test keys on a live page. Not a breach, but a tell that the wrong build went out the door.
04Open Graph + Twitter card
Link preview
Your link unfurls as a card, not a blank gray box, when you post it.
Preview image present
og:image, the picture that renders when your page is shared to X, LinkedIn, Slack, or iMessage. Missing means a blank box on the exact day you want it to look sharp.
Preview title present
og:title, so a shared link shows your headline instead of a bare URL. We also capture og:description and twitter:card so you can see the full unfurl.
0513 reachability & runtime checks
Up & resolving
The page is actually up, indexable, and clean, for a logged-out visitor.
HTTP status
4xx and 5xx codes that real visitors hit. A 5xx caps your score hard.
Redirect loop
A redirect that points back at itself and never resolves.
Too many redirects
A hop chain so long the browser gives up before reaching your page.
HTTPS downgrade
A redirect that drops you from https to http partway through the chain.
Silent URL change
The final URL’s host or path differs from the one you submitted, usually a misconfigured redirect carrying visitors somewhere you did not intend.
Canonical redirects, classified right
apex ↔ www and trailing-slash redirects are recognized as normal and not false-flagged. We only raise an alarm when a param is lost or the scheme drops.
Accidental noindex
A robots meta set to noindex on a page you meant to be public. Critical on landing, pricing, and signup URLs.
Page fully loads
Navigation errors that stop the page from rendering for a fresh visitor.
Scan completes in time
A page so slow it times out before checks finish is a page your visitors are abandoning too.
Console errors on load
JavaScript errors thrown the moment the page loads.
Failed network requests
Assets or APIs the page tried to load and could not. Three or more escalates.
Bot-wall detection
When a page blocks automated visitors, we say we could only partially verify it, instead of pretending everything is fine.
Private-network guard
We refuse to scan internal or reserved IP targets, so the scanner can never be aimed at private infrastructure.
06
What we don’t check
A short, honest list beats a long, padded one. These are out of scope on purpose.
Whole-site crawls
Up to 5 money pages you choose, across any of your sites, not every URL on them. Depth on what earns, not breadth for a bigger number.
Page speed & Core Web Vitals
We are a breakage monitor, not a performance grader. We will tell you the page is down, not that it is 200ms slow.
Accessibility & on-page SEO
No a11y or SEO scoring. Plenty of tools grade those once; we watch conversion stay un-broken, every day.
Logged-in & server-side flows
We see what a logged-out visitor sees. Checkout completion, server-side events, and CRM routing live outside our view.
Why a daily cloud monitor, not a one-time checklist
Runs while you sleep
No app to keep open, no machine that has to stay awake. The scan runs in the cloud on a schedule and emails you as soon as a check catches a break.
Catches breaks, not just launch-day misses
A pre-launch checklist is true for about an hour. The breaks that actually cost you happen on the next deploy or CMS edit. So we re-check every day.
Watches a moving target
We remember yesterday’s scan. A pixel that vanishes or a price that quietly changes only shows up when something compares the page to how it looked before.
Run every one of these on your page, free.
No signup for the first scan. Most finish in seconds.