Transport and headers
HTTPS enforcement, TLS response, HSTS, framing policy, content type sniffing, referrer policy, and content security policy where the response exposes them.
The public report checks the signals a visitor can observe, explains what responded, and marks what it could not measure.
The scan combines response headers, page source, and a guarded browser read to surface the issues worth reviewing first.
HTTPS enforcement, TLS response, HSTS, framing policy, content type sniffing, referrer policy, and content security policy where the response exposes them.
Form destinations, mixed-content requests, sensitive cookie flags, and the scripts, frames, and assets a public page references.
When a site exposes the relevant endpoints, the report checks author profiles, uploads listings, XML-RPC reachability, and version disclosures.
The scanner is built to inspect public websites without treating an arbitrary URL as a safe network destination.
Private and local addresses are refused. Outbound connections are constrained, redirects are bounded, and rendered-page work runs in a guarded Chrome pool with time limits and retries.
Account work lives behind private access. Releases are reviewed before they are published.
A public report can tell you what a visitor and a public fetch can observe at scan time. It cannot certify a whole application, an internal network, or compliance with a specific standard.
When a page does not respond, a check is unavailable, or a site blocks the read, the report says so. It does not turn missing evidence into a passing score.
Run the report against a property website in about a minute.