Authorized deep scan
Scan the real server — not just the surface.
Our free scan reads what's public. The deep scan goes further: open ports, exposed services and version-level vulnerabilities on your actual origin server — the one behind your CDN. Because that's intrusive, we run it only after you prove you own the domain and authorize the test.
How it works
- 1Confirm your work email — so we can deliver the report to a verified inbox.
- 2Prove domain control — add one DNS TXT record we give you. This is what makes the scan legal and safe.
- 3We scan your verified origin from an isolated WoneShield scanner and email your full report.
Active scanning of a system you don't own or aren't authorized to test is illegal. Verification and your explicit authorization aren't red tape — they're what separate a security service from an attack. We enforce both.