Methodology

What the scanner does

It makes one ordinary HTTPS request for the address you give, follows a limited number of redirects, and reads the response. It reads bounded amounts of data and gives up at a fixed time limit, so a slow or enormous page cannot hold the service open.

What it refuses to do

It will only contact public internet addresses. Anything that resolves into a private network is refused before a connection is made, and that refusal happens the same way on every redirect the site sends. It never submits a form, never logs in, and never sends a request designed to provoke a fault.

Where the repair advice comes from

From a written, versioned knowledge base — not from a model and not from the scanned page. Every record carries the citation it was written from, and the provenance label in a report is generated from that citation. The complete provenance figures are in Why we don't guess.

How findings are ordered

By impact, discounted by how confident the scan is in what it observed. A check the scanner is unsure about cannot be reported as a high-priority problem, whatever its theoretical impact.

Ready to check a website?

Run a scan