Last updated July 25, 2026. What we check, what we never do, and how to keep your site out of our scans.
HTTP security headers and TLS/certificate metadata, DNS/robots/ sitemap metadata, public JavaScript and asset inspection, safe HEAD/GET requests against obvious public files, and technology fingerprinting. All of it is passive and uses only what a normal visitor's browser would already see.
No exploit attempts or destructive tests, no form fuzzing or credential testing, no authenticated or internal scans without your explicit consent, no high-volume crawling, and nothing designed to degrade a site's availability.
Checks that go beyond public data (like repository or database configuration review) only run after you verify you own the target and grant explicit access. We never scan authenticated areas of a site without that verification.
Our scanner is rate-limited and designed to be indistinguishable from a single ordinary visitor's traffic. If a site owner ever believes our scan caused a problem, contact us immediately at [email protected] and we'll investigate.
If you don't want your site scanned, even if someone else submits your URL, email [email protected] from an address associated with the domain and we'll add it to our exclusion list.
See also our Responsible Disclosure policy for reporting a vulnerability in our own platform.