HomeFeaturesDocumentationContactDownload
Browse the docs

Installation

How to install SiteCMD on macOS, Windows, and Linux.

SiteCMD builds for macOS 11 or newer (Apple Silicon and Intel), Windows (x86_64), and Linux (x86_64). The download page picks the right build for your OS, and documents the signed SHA256SUMS steps if you want to verify a download before running it.

macOS

You'll get a single universal .dmg that runs natively on both Apple Silicon and Intel. To install:

  1. Open the .dmg.
  2. Drag SiteCMD to your Applications folder.
  3. Eject the disk image.
  4. Open Applications and double-click SiteCMD.

First launch

SiteCMD is signed with an Apple Developer ID and notarized by Apple, so macOS Gatekeeper opens it normally. You won't see the "cannot be opened because the developer cannot be verified" warning. The first time you open any app downloaded from the internet, macOS may show a one-time "SiteCMD is an app downloaded from the Internet. Are you sure you want to open it?" confirmation; click Open.

The auto-updater is also cryptographically signed, so updates after the first launch don't trigger extra prompts.

Windows

You'll get an .exe installer for x86_64 (SiteCMD_<version>_x64-setup.exe). Run it and follow the steps.

First launch

The installer is code-signed with Azure Trusted Signing, so you won't see an "unknown publisher" warning. SmartScreen builds trust per signing identity over time; until that reputation is established, it may still show a "Windows protected your PC" prompt. If it does, click More info, then Run anyway. It stops once the signature has enough installs behind it.

Linux

You'll get an .AppImage for x86_64. It runs directly, no install step:

chmod +x SiteCMD_<version>_amd64.AppImage
./SiteCMD_<version>_amd64.AppImage

Web scans on Linux currently skip the browser layer, which is where Core Web Vitals and accessibility analysis come from. The Linux webview gives SiteCMD no private-network subresource filter, so the app refuses to load pages in it rather than expose your local network. Every other check runs. Privacy and data has the details.

Auto-updates

The desktop app checks for updates in the background against releases.sitecmd.com and prompts you when a new version is ready. You install on your schedule, the app does not force-restart. Update checks make a small network request to fetch the latest release manifest. Nothing about your scans, source code, or projects is sent in that request.

What gets installed

SiteCMD is a single application plus a per-user data directory:

  • App bundle: /Applications/SiteCMD.app (macOS), a per-user directory under %LOCALAPPDATA% (Windows; the installer runs without administrator rights), or wherever you keep the AppImage (Linux).
  • Data directory: the standard Tauri app-data path for your OS. This is where the local SQLite database, scan history, and audit log live. SiteCMD does not upload this directory or mirror the local database. A connected site sends only the fields documented under Privacy & data.
  • Application logs: the operating system's separate per-app log directory under com.sitecmd.desktop. The exact platform paths are listed under Troubleshooting.
  • OS keychain entries: desktop integration credentials (Cloudflare, GA4, GitHub, Plausible, and so on) are stored in your operating system's credential store. They're never written to the SiteCMD database. Connected Vercel or Netlify credentials are a separate opt-in stored encrypted by the connected service.

Uninstalling

Remove the application bundle the same way you remove any other app on your OS.

To wipe local data as well, delete the SiteCMD app-data directory. Desktop integration credentials live in your OS keychain or credential store and aren't removed by uninstalling the app. If you want a clean local slate, search for "SiteCMD" entries in Keychain Access (macOS), Credential Manager (Windows), or secret-tool / GNOME Keyring (Linux) and delete them.

Uninstalling or deleting local data does not erase a connected site's remote state. Before uninstalling, use Settings → Connected → Erase Site Data for immediate remote erasure. If the app is already gone, contact us for an account-data request.