Security scanner
What Webforta Scan checks, how it behaves and its limitations.
Webforta Scan performs a safe, read-only assessment of your verified website using public HTTP and HTTPS requests from Cloudflare’s network.
Checks
- HTTPS availability and HTTP-to-HTTPS redirect behaviour.
- Security headers: Strict-Transport-Security, Content-Security-Policy, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, permissive CORS.
- Cookie flags: Secure, HttpOnly, SameSite.
- Mixed content and forms that submit over HTTP on the homepage.
- Technology and version disclosure (Server, X-Powered-By, generator tags) and platform identification (WordPress, Drupal, Joomla, Shopify and others).
- Commonly exposed files (77 checks), each confirmed by content signature: .git and SVN metadata, .env files and configuration backups (WordPress, Joomla, Drupal), private keys and cloud credentials, editor deployment settings, SQL dumps and backup archives, error logs, debug endpoints (ELMAH, ASP.NET trace, Spring actuator, Symfony profiler), database admin tools, dependency lock files, permissive cross-domain policies, public API descriptions, and XML-RPC.
- Directory listing on the homepage and presence (and expiry) of security.txt.
- Certificate expiry from public Certificate Transparency logs.
- Error handling: debug pages, stack traces, PHP errors and server versions on a missing page; soft 404s.
- CORS: whether the site reflects an arbitrary Origin, with or without credentials. HTTP methods advertised (WebDAV, PUT, DELETE, TRACE). Gaps in an existing Content-Security-Policy.
- Known vulnerabilities: WordPress core, plugin and theme versions read from public files and matched against public CVE records (looked up through OpenCVE; findings listed by CISA as actively exploited are flagged first); JavaScript libraries (jQuery, Bootstrap, AngularJS and about 70 more) matched against the retire.js database; scripts from CDN domains known to have served malware.
- Outdated and end-of-life software: WordPress core and plugins versus wordpress.org, PHP versions past their security support, Drupal 7/8/9, Joomla 3 and older, Magento 1.
- WordPress username enumeration through the REST API and author archives (usernames are counted, never stored).
- Attack surface from public data: hostnames in Certificate Transparency logs (flagging staging, admin and similar names), DNSSEC, MTA-STS and TLS-RPT.
- Technology profile: server, frameworks, and the CDN or WAF in front of the site.
Behaviour
- Up to about 150 requests to the site per scan, at most 6 in parallel, each limited in time and response size. All are GET requests except one OPTIONS request that reads the advertised methods.
- Only the verified hostname (and its www/apex variant) is contacted. Third-party scripts are identified from their URLs and are not downloaded.
- User agent: WebfortaScanner/1.0 (+https://webforta.com/docs/scanner).
- Cloaking check: the homepage is also loaded three times as a regular desktop browser, as Googlebot, and as a phone visitor arriving from Google search, because hacked sites often show spam or redirects only to search engines or search visitors. These three requests do not carry the Webforta user agent.
- Every request target is resolved and checked against private, loopback, link-local and reserved address ranges before connecting, including after redirects.
Limitations
A scan without findings does not mean a site is secure or free of malware. From the outside, a scan cannot see server-side files (the optional WordPress plugin checks those from inside the site), authenticated areas, plugins that are not publicly referenced, or vulnerabilities that require active exploitation to confirm. Software versions read from public files can differ from what is installed; confirm each vulnerability finding in the site itself.
- Certificate data comes from CT logs, which can lag a renewal by a few hours.
- Sites that block automated traffic or Cloudflare’s network may be reported as unreachable.
- Detection is heuristic; use "Mark false positive" to suppress a finding on future scans.