Scan Policy

Exactly what the Wardvo free audit scanner does – and never does.

Our free scanner is designed to be safe, legal and polite. Here is exactly what it does.

What the scanner does

Loads your homepage and one made-up address (to test “page not found” handling), exactly like a normal visitor.

Reads the response headers and performs a standard HTTPS handshake to check your certificate.

Looks up public DNS records (SPF and DMARC) for your domain.

What the scanner never does

No port scanning, password guessing, form submission, vulnerability probing, crawling of hidden files, or anything that could affect your website’s operation.

Limits

Scans are rate-limited, results are cached for 15 minutes to avoid repeat requests, and internal or private network addresses are refused.

Identification

Requests identify themselves with the user agent WardvoScan/1.0 (+https://wardvo.com/scan-policy/).

Deeper testing

Vulnerability testing and any active security testing are performed only for clients who sign a written authorization confirming they own or control the systems in scope.

Report a concern

If you believe our scanner was used on your site without permission, email [email protected]. Our security contact is published at /.well-known/security.txt.