Skip to content

Writing

What a free scan may actually do to you

We built a public scanner and drew the line at what a browser does. Here is why, and what it costs us.

A public page where a stranger types an address and we make a request is the one place in a security product where scanning happens without written authorisation. Most free scanners handle this with a disclaimer. A disclaimer is not a boundary.

So we drew one: we do what a browser does and nothing else. One page load, the certificate, the response headers, the cookies that response sets, and public DNS.

The things we decided not to do

We do not request a path nobody linked to. Free scanners routinely try /.git/HEAD, /.env, /admin and a list of backup filenames. Nobody’s browser asks for those, so a request for one is a probe, it appears in the target’s logs as an attack, and it is not ours to make against a domain typed by somebody we cannot identify.

For MCP endpoints we complete the protocol handshake — which is the exchange the specification exists to invite — and we never call a tool. Not one, not a read-only one. Calling a tool is acting inside somebody else’s system.

What it costs

A lot. The checks we can make are the shallow ones, and a clean result means only that the part your visitors can see is in order. Our results page says that in those words, and the section listing what it cannot tell you is longer than the section listing what it did.

We also refuse to give a grade. Every free scanner ends in a letter because a letter gets screenshotted, but a grade over what a browser can see implies that is the whole question. Somebody with an A and an unauthenticated admin panel has been misled, by us.

What we get back

Every finding on that page can be reproduced by the reader in their browser’s developer tools in about a minute. A finding somebody can check themselves is worth five they have to take on trust — and a first impression built on a claim they verified is a better start than one built on a number we made up.