The pentest checks a website within seconds for typical weak spots in the configuration, such as missing security headers, insecure redirects or openly reachable login paths. For each problem you get concrete hints on how to fix it.
What does the scan do?
The scan is passive and harmless. It fetches the page like a normal visitor, tests whether the HTTP variant redirects, and only asks whether five typical paths (/login, /wp-login.php, /admin, /administrator, /user/login) exist. There are no attacks, and nothing is changed. Internal addresses are blocked, only publicly reachable targets are scanned.
Start a scan
- Sign in. The pentest is only usable with an account.
- Open Pentest in the navigation (group Tools)
- Enter the Target URL, e.g.
https://your-website.com. Without a scheme,https://is added. - Click Start scan
While the scan runs it says "Scan running ...", and afterwards the report is prepared.
The report
Right at the top are the key facts about the target:
| Item | Meaning |
|---|---|
| Target | The address you entered |
| Final URL | Where the request ended up after redirects |
| HTTP status | The server's response |
| Response time | How fast the server answered |
| Technologies | Detected CMS, frameworks and servers |
| Score | Overall value from 0 to 100 |
The score
The score starts at 100. Each critical problem costs 22 points, each warning 8. A high score doesn't mean the site is secure, only that the quick check found nothing conspicuous.
The findings
The findings are sorted into four groups:
| Group | Meaning |
|---|---|
| Critical issues | Fix immediately |
| Room for improvement | Improve soon |
| Notes | Information without rating |
| Passed | This point is fine |
Each finding names:
- Found: what the scan observed
- Why this matters: the risk behind it
- Where to change it: for example web server, CMS or reverse proxy
- How to fix it: the way to the solution, often with a code example you can copy (Copy code), for Apache or PHP, say
What is checked?
Headers & TLS
- HTTPS: is the site delivered encrypted, and does
http://redirect permanently tohttps://? - TLS certificate: can it be fully validated?
- Security headers: Content-Security-Policy, Strict-Transport-Security (HSTS), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- Cookie flags: do cookies that are set have Secure, HttpOnly and SameSite?
Surface Scan
- Forms and password fields: this is where attackers could try logins and input
- Form actions: does a form send to an unencrypted HTTP endpoint?
- Typical entry points: are login or admin paths publicly reachable?
- Mixed content: does an HTTPS page load resources over HTTP?
- Directory listing: does the server show directory contents?
Tech Fingerprint
- Server header and X-Powered-By: do they reveal software and version?
- Detected technologies: CMS, framework and server signatures
Common measures
- Enforce HTTPS: set up a permanent 301 redirect from HTTP to HTTPS
- Set HSTS: with it browsers only connect encrypted from then on
- Add security headers: above all X-Content-Type-Options, X-Frame-Options and a CSP
- Secure cookies with Secure, HttpOnly and SameSite
- Protect login areas: rate limits, brute-force protection, two-factor sign-in and, if you can, access only from certain IPs
- Hide version details: remove the Server and X-Powered-By headers or tone them down
- Disable directory listing
Frequently asked questions
The scan reports "The target could not be reached"
Either the address isn't publicly reachable, you misspelled it, or the server blocks the request. Internal addresses (e.g. localhost) are never scanned.
My site has 100 points, is it secure?
No. The score only rates the points that are checked. It says nothing about weaknesses in the application itself, such as SQL injection or outdated plugins.
Why are some points "Note" instead of warning?
When something cant be checked reliably, e.g. the redirect behavior, it is shown as information instead of an error.
May I scan other people's websites?
No. Only scan your own websites or ones you've been commissioned in writing to check.