Vulnerabilities are scored using the CVSS standard and automatically verified wherever possible. Findings cover the full spectrum: the web application, SSL/TLS configuration, access credentials and network services.
🤖
AI remediation prompts are guidance only. Each finding includes a ready-made prompt for Claude, ChatGPT or Cursor. AI suggestions must be reviewed by a qualified developer before being applied. Do not execute AI-generated commands without understanding their impact. Scaneo does not verify AI output.
In addition to your primary domain, we also check subdomains, SPF & DMARC configuration, WHOIS records, domain takeover risks and lookalike domains used for phishing.
We identify email addresses associated with your domain and cross-check them against data breach databases to identify compromised accounts and leaked credentials.
We check publicly reachable network services and open ports. For each discovered server we identify the operating system, running services and known vulnerabilities.
Note: Findings from scanning an IP address may reflect the infrastructure of a shared hosting provider rather than the customer's application directly. If an IP belongs to a known cloud or hosting provider, vulnerabilities and open ports may be shared with other tenants on the same platform.
We map publicly accessible paths, files and directories of the target website. We focus on CMS installations, hidden or sensitive files, backup files and misconfigured endpoints. JavaScript libraries are checked for known CVE vulnerabilities.
⚠ These paths may expose sensitive functionality or files. Review manually whether they should be publicly accessible. Examples: uploads, test, backup, config, admin.
🔒 Paths that returned a 4xx (Forbidden / Unauthorized) response. These paths exist on the server but access was denied — they may indicate hidden admin panels, protected areas or misconfigured access control.
🚨 Paths that returned a 5xx (Server Error) response. These may expose stack traces, debug output or internal error details.