Your site tells every visitor something.Read what it says.
Headers, cookies, TLS, redirects, DNS — a browser collects all of it before it draws a single pixel, and so does everyone else’s. This reads exactly what they get. Free, no account.
10 checks · results on this page · nothing stored · three scans a day
What it sends
10 checks, every one of them something a browser does opening your front page: fetch it, complete the TLS handshake, follow the http → https redirect, send a single cross-origin preflight, and read your public DNS — which a resolver answers and which never touches your servers at all. The rest is analysis of the page already fetched.
It does not crawl. It does not guess at /.git or /.env. It does not enumerate your subdomains or your plugins, and it never tries a login. Those checks exist in the product, and they run only on a domain whose ownership you have proven.
What we keep
Not the findings. They are computed for your request, sent to your browser, and gone — which is also why there is no link to share them with. Holding a list of a company’s weak points because somebody typed its name into a free tool is not something we want to be doing at any scale.
We record that an address asked us to look at a hostname, and nothing else. A tool that sends traffic on a stranger’s instruction should be able to say who asked.
The reasoning is written out in the testing authorization notice.