VFT369 / SCANNER / GUIDE

Website Security Scanner — guide

A free, non-intrusive check of how well your website is configured: encryption, security headers, cookies and common exposed files. Currently in beta.

[ RUN A SCAN ]

1. How to run a scan

  1. Open vft369.com/#scan.
  2. Enter the website, e.g. example.com (no https:// needed).
  3. Enter your email address.
  4. Tick “I own this website or am authorised to test it”. The button stays disabled until you do.
  5. Choose Quick or Full, then press RUN SCAN. Most scans finish in under 20 seconds.

More scans

Without an account you can run 5 scans an hour. For more, sign in with your email on the scan page: we send a one-time code, no password needed, and you can see your recent scans. Scans of domains you have verified also get a higher limit.

2. Quick scan vs full scan

Quick scanFull scan
Who can use itAnyone, for a site they are authorised to testVerified domain owners only
HTTPS certificate & TLS version✓✓
HTTP → HTTPS redirect✓✓
Security headers and their quality (CSP, HSTS, clickjacking, MIME sniffing, referrer)✓✓
Cookie flags (Secure, HttpOnly, SameSite)✓✓
Server version disclosure✓✓
Exposed sensitive files: .env, .git, backups, phpinfo.php, server-status, .DS_Store—✓

A quick scan only reads what any browser sees when it visits your homepage. A full scan also asks for a handful of well-known file paths that should never be public. That is why it needs proof that you control the domain.

Neither scan is a penetration test. They don't log in, submit forms, guess passwords or attempt to exploit anything. A good grade means your configuration is sound, not that the site is free of vulnerabilities.

3. Verifying that you own a domain (full scan)

When you request a full scan of an unverified domain, the scanner shows you a personal token for that domain. Prove control with either method:

Option A — DNS record (recommended)

At your domain or DNS provider, add a TXT record:

TypeTXT
Name / Host@ (the domain itself, e.g. example.com)
Valuevft369-verify=<your token>

DNS changes usually appear within minutes but can take up to an hour.

Option B — verification file

Upload a plain-text file containing only your token to:

https://example.com/.well-known/vft369-verify.txt

Then press CHECK AGAIN & SCAN. The token is tied to your domain and never changes, so you can leave the record in place for future full scans. Remove it to revoke access.

4. Reading your report

Need help fixing something? Use BOOK A CALL on the results, or the contact form.

5. API (beta)

The same scanner is available as a JSON endpoint for scripts and server-side tools. It is in beta: the format may change, and the limits below apply. Calls from other websites' browser code are blocked, so call it from a server or terminal.

Endpoint

POST https://www.vft369.com/api/scan
Content-Type: application/json

Run a scan

curl -s https://www.vft369.com/api/scan \
  -H 'Content-Type: application/json' \
  -d '{
    "action":  "scan",
    "target":  "example.com",
    "email":   "you@example.com",
    "tier":    "quick",
    "consent": true
  }'
FieldRequiredMeaning
actionnoscan (default), verify_token or verify_check
targetyesDomain or URL. Ports 80 and 443 only.
emailscanWhere we can reach you about this scan
tiernoquick (default) or full
consentscanMust be true: you confirm you own or are authorised to test the target
marketingnotrue to receive occasional security tips

Response (shortened)

{
  "host": "example.com",
  "tier": "quick",
  "score": 86,
  "grade": "B",
  "scanned_at": "2026-10-11T19:56:14Z",
  "duration_ms": 2140,
  "counts": { "high": 0, "medium": 1, "low": 1, "info": 0, "pass": 9 },
  "findings": [
    {
      "check": "hsts",
      "severity": "medium",
      "title": "HSTS max-age is short",
      "detail": "…",
      "fix": "…"
    }
  ],
  "scope": "Automated, non-intrusive surface scan …",
  "report_html": "<!doctype html>…"
}

Domain verification via the API

# 1. Get your token and instructions
curl -s https://www.vft369.com/api/scan -H 'Content-Type: application/json' \
  -d '{"action":"verify_token","target":"example.com"}'

# 2. After adding the DNS record or file, check it
curl -s https://www.vft369.com/api/scan -H 'Content-Type: application/json' \
  -d '{"action":"verify_check","target":"example.com"}'
# → {"domain":"example.com","verified":true,"method":"dns"}

Limits

Errors

Errors return a JSON body like {"error": "rate_limited", "message": "…"}.

HTTPerrorMeaning
400invalid_email, consent_required, invalid_tier, invalid_targetFix the request
403verification_requiredFull scan of an unverified domain. The response includes a verify object with your token.
422blocked_target, dns_failedTarget can't be scanned or doesn't resolve
429rate_limitedWait and try again later
503 / 504unavailable, timeoutTemporary problem; retry later

Need higher limits, scheduled scans or API keys for your team? Get in touch. These are planned for the paid service.

6. Rules & privacy