Security Protocols

This page sets out exactly what our checks do to a website, so you can recognise them in your logs and see that nothing we do is harmful.

Public access only

We only request what any visitor could request. We never ask for, or use, admin logins, FTP details or passwords. We never install anything on your site, and we never change anything on it.

How our requests look

  • Our requests use an ordinary desktop browser user agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36.
  • When we check whether we can reach a site that has blocked us, we repeat the check with the header X-PC-Performance carrying a key unique to your domain. That key is shown to you on our site so you can allow it through your firewall.
  • Some checks load your page in a real browser, and the full report includes a screen reader session on a Mac reading your page.

What we request

Your pages. Your home page, and up to ten further pages found through your sitemap and links. Links on those pages are checked with a HEAD request, which asks for the headers only.

Standard WordPress files. /readme.html, /license.txt and /feed/, which reveal the WordPress version if they are left in place.

Files that should never be public. We check whether these answer at all: /wp-content/debug.log, /wp-config.php.bak, /.env, /.git/HEAD, /phpinfo.php, /backup.zip and /database.sql. If one answers, we report that it is exposed.

Directory listings. Whether /wp-content/, /wp-content/plugins/, /wp-content/uploads/ and /wp-includes/ list their contents.

User names. Whether /?author=1 or /wp-json/wp/v2/users reveal account names, which makes password attacks easier.

XML-RPC. A GET to /xmlrpc.php, and if it answers, one request asking it to list its methods, so we can tell whether pingback is switched on. This reads a list; it does not use any of the methods.

Login surface. Whether /wp-login.php and /wp-admin/ are reachable. We only load them; we never try to sign in.

What we never do

  • We never try to sign in, guess passwords or test logins.
  • We never submit your forms or place orders.
  • We never attempt to exploit a weakness we find; we report it.
  • We never load test your site or send large volumes of traffic.

How much traffic we send

We check one site at a time. Responses are kept for 25 minutes and reused across our checks, so the same page is not requested again and again during a run.

What we keep

The responses we receive are kept as evidence behind the findings in your report, and deleted after six months, as set out in our Privacy Policy.

Seen us and did not ask?

We only check sites at the request of someone who confirms they are authorised to have them checked. If you see our requests and did not ask for a report, email [email protected] and we will look into it.