Security Testing Authorization Terms
What you confirm when you ask Webforta to assess a website.
Your confirmation
By adding a website and starting a scan or monitoring, you confirm that you own the website or hold written authorization from its owner to perform automated, non-intrusive security assessments, and that doing so does not breach any agreement with your hosting provider.
What Webforta does
- Read-only HTTP and HTTPS GET requests to the verified hostname (and its www/apex variant), plus one OPTIONS request that only reads which methods the server advertises.
- Requests for a fixed list of commonly exposed files, each matched by content signature, and for a random non-existent path to see how errors are handled.
- A handful of pages linked from the homepage, and scripts hosted on the verified site, read to identify software versions.
- One request carrying a made-up Origin header, to check whether the site trusts any origin (CORS).
- DNS lookups through public resolvers, Certificate Transparency log searches, and lookups in public vulnerability databases. Third-party sites are not scanned.
- Typical volume: up to about 150 requests per scan, at most 6 in parallel; one request per monitoring check.
What Webforta does not do
- No exploitation, payload injection, credential guessing or authentication attempts.
- No port scanning beyond 80 and 443.
- No crawling beyond the homepage, a handful of pages it links to, and the listed paths.
- No denial-of-service or load testing.
Identification
Requests identify themselves with the user agent "WebfortaScanner/1.0 (+https://webforta.com/docs/scanner)".
Other policies: Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use Policy · Security Testing Authorization Terms · Data Retention and Deletion Policy · Responsible Disclosure Policy ·