HomeFeaturesDocumentationContactDownload

Download SiteCMD

Scan your live site and source code, hand the fixes to your AI editor, and verify they stay fixed. Free and local-first, with no account to create.

v1.5.0 · released 2026-09-22 · macOS 11+, Windows x64, Linux x64

The SiteCMD dashboard with a site's health score, open issues, and recent activity.

Set it up from your AI agent

Two steps. Your agent registers the MCP server itself, adds the project, runs the first scan, and reports back. From there, ask it to fix anything it found, and SiteCMD verifies each fix.

  1. Step 1

    Install SiteCMD

    Open it once and leave it running. The first launch puts the MCP server and the local database in place.

    Download for macOS (Apple Silicon)
  2. Step 2

    Paste this into your agent

    Works in Claude Code, Codex, Cursor, and Windsurf with Node 22.22.1 or newer. Other editors take one config block; see AI editor setup.

    Connect to SiteCMD over MCP and scan this project.
    
    SiteCMD is installed and has been opened once, so its MCP server script is at one of these paths. Use the absolute path for this OS:
    
    - macOS: `~/Library/Application Support/com.sitecmd.app/sitecmd-mcp/sitecmd-mcp.mjs`
    - Linux: `$XDG_DATA_HOME/com.sitecmd.app/sitecmd-mcp/sitecmd-mcp.mjs`, or `~/.local/share/com.sitecmd.app/sitecmd-mcp/sitecmd-mcp.mjs` when XDG_DATA_HOME is unset
    - Windows: `%LOCALAPPDATA%\com.sitecmd.app\sitecmd-mcp\sitecmd-mcp.mjs`
    
    Register it as an MCP server named `sitecmd` in your own config, running `node --disable-warning=ExperimentalWarning "<script path>"`. Node 22.22.1 or newer must be on the PATH.
    
    - Claude Code: `claude mcp add --scope user sitecmd -- node --disable-warning=ExperimentalWarning "<script path>"`
    - Codex: `[mcp_servers.sitecmd]` in `~/.codex/config.toml`
    - Cursor: `~/.cursor/mcp.json`
    - Windsurf: `~/.codeium/windsurf/mcp_config.json`
    
    If you had to add it, tell me to restart you and paste this again.
    
    Once the sitecmd tools are available:
    
    1. If `get_projects` does not list this repository's site, run `npx --yes @sitecmd/cli init <url> --yes` from the repository root. Ask me for the URL if you cannot tell.
    2. Call `run_scan` with scope `full` and wait for it.
    3. Summarize the top issues from `get_issues`, and let's discuss what we should fix.
    

Verify your download

Every release publishes a signed SHA-256 checksum list. Verify that signature with the same minisign key used for updater bundles and CLI archives before trusting a checksum. Cross-check the key against the public repository rather than relying on this site as its only source.

Authenticate the checksum list

minisign -Vm SHA256SUMS -x SHA256SUMS.minisig -P RWTtzNh0gmMU/8O1AJBbQbUEy9oD5lpqL/dV0qRqlpsCldfWNWgxr5kE

Check a macOS installer

shasum -a 256 -c --ignore-missing SHA256SUMS
# verifies SiteCMD_1.5.0_universal.dmg when it is in this directory

Check a CLI archive

base64 --decode < sitecmd-cli_1.5.0_darwin-universal.tar.gz.sig > archive.minisig
minisign -Vm sitecmd-cli_1.5.0_darwin-universal.tar.gz -x archive.minisig -P RWTtzNh0gmMU/8O1AJBbQbUEy9oD5lpqL/dV0qRqlpsCldfWNWgxr5kE

Before you install, here is what leaves your machine

See the network boundaries and verify them yourself

  • Your files stay on your machine

    The desktop app does not upload your source files, and scan results stay local unless you connect a site yourself. There is no account to create, and the app does not contact the connected service until you opt in for a site.

  • A small, named set of calls

    Beyond fetching the site you scan, the app makes a small, named set of calls: an update check, a public domain-registry lookup, and Google PageSpeed when you open Web Vitals. Web Scan sends recognizable front-end library names and versions to api.osv.dev for advisory checks. The separate Updates workflow sends installed package names and versions to dependency and vulnerability services. Existing licenses can also validate and fetch maintained-catalog updates. Connected sites use the separate hosted-service calls disclosed on the Trust page.

  • Telemetry is opt-in

    Analytics and crash reports are off by default and opt-in.

Local-first

Scans, history, and findings are stored on your machine by default. Work offline without a hosted account, or explicitly connect a site when you want hosted automation.

MCP server

A built-in MCP server hands ranked issues and detailed fix prompts straight to Claude Code, Cursor, and other AI editors.

Verified fixes

Hand a ranked finding to your coding agent, re-run the check, and keep the issue closed only when SiteCMD verifies the fix.