VFT369 / SCANNER / GUIDE
Website Security Scanner — guide
A free, non-intrusive check of how well your website is configured: encryption, security headers, cookies and common exposed files. Currently in beta.
[ RUN A SCAN ]1. How to run a scan
- Open vft369.com/#scan.
- Enter the website, e.g.
example.com(nohttps://needed). - Enter your email address.
- Tick “I own this website or am authorised to test it”. The button stays disabled until you do.
- Choose Quick or Full, then press RUN SCAN. Most scans finish in under 20 seconds.
More scans
Without an account you can run 5 scans an hour. For more, sign in with your email on the scan page: we send a one-time code, no password needed, and you can see your recent scans. Scans of domains you have verified also get a higher limit.
2. Quick scan vs full scan
| Quick scan | Full scan | |
|---|---|---|
| Who can use it | Anyone, for a site they are authorised to test | Verified domain owners only |
| HTTPS certificate & TLS version | ✓ | ✓ |
| HTTP → HTTPS redirect | ✓ | ✓ |
| Security headers and their quality (CSP, HSTS, clickjacking, MIME sniffing, referrer) | ✓ | ✓ |
| Cookie flags (Secure, HttpOnly, SameSite) | ✓ | ✓ |
| Server version disclosure | ✓ | ✓ |
Exposed sensitive files: .env, .git, backups, phpinfo.php, server-status, .DS_Store | — | ✓ |
A quick scan only reads what any browser sees when it visits your homepage. A full scan also asks for a handful of well-known file paths that should never be public. That is why it needs proof that you control the domain.
3. Verifying that you own a domain (full scan)
When you request a full scan of an unverified domain, the scanner shows you a personal token for that domain. Prove control with either method:
Option A — DNS record (recommended)
At your domain or DNS provider, add a TXT record:
| Type | TXT |
|---|---|
| Name / Host | @ (the domain itself, e.g. example.com) |
| Value | vft369-verify=<your token> |
DNS changes usually appear within minutes but can take up to an hour.
Option B — verification file
Upload a plain-text file containing only your token to:
https://example.com/.well-known/vft369-verify.txt
Then press CHECK AGAIN & SCAN. The token is tied to your domain and never changes, so you can leave the record in place for future full scans. Remove it to revoke access.
4. Reading your report
- Grade & score: you start at 100. Each high finding costs 20 points, medium 10, low 4.
- Findings: each one says what is wrong, why it matters and how to fix it.
- Passed checks: the things you already got right.
- DOWNLOAD REPORT: saves a self-contained HTML report you can share with your developer or host.
Need help fixing something? Use BOOK A CALL on the results, or the contact form.
5. API (beta)
The same scanner is available as a JSON endpoint for scripts and server-side tools. It is in beta: the format may change, and the limits below apply. Calls from other websites' browser code are blocked, so call it from a server or terminal.
Endpoint
POST https://www.vft369.com/api/scan
Content-Type: application/json
Run a scan
curl -s https://www.vft369.com/api/scan \
-H 'Content-Type: application/json' \
-d '{
"action": "scan",
"target": "example.com",
"email": "you@example.com",
"tier": "quick",
"consent": true
}'
| Field | Required | Meaning |
|---|---|---|
action | no | scan (default), verify_token or verify_check |
target | yes | Domain or URL. Ports 80 and 443 only. |
email | scan | Where we can reach you about this scan |
tier | no | quick (default) or full |
consent | scan | Must be true: you confirm you own or are authorised to test the target |
marketing | no | true to receive occasional security tips |
Response (shortened)
{
"host": "example.com",
"tier": "quick",
"score": 86,
"grade": "B",
"scanned_at": "2026-10-11T19:56:14Z",
"duration_ms": 2140,
"counts": { "high": 0, "medium": 1, "low": 1, "info": 0, "pass": 9 },
"findings": [
{
"check": "hsts",
"severity": "medium",
"title": "HSTS max-age is short",
"detail": "…",
"fix": "…"
}
],
"scope": "Automated, non-intrusive surface scan …",
"report_html": "<!doctype html>…"
}
Domain verification via the API
# 1. Get your token and instructions
curl -s https://www.vft369.com/api/scan -H 'Content-Type: application/json' \
-d '{"action":"verify_token","target":"example.com"}'
# 2. After adding the DNS record or file, check it
curl -s https://www.vft369.com/api/scan -H 'Content-Type: application/json' \
-d '{"action":"verify_check","target":"example.com"}'
# → {"domain":"example.com","verified":true,"method":"dns"}
Limits
- Without an account: 5 scans per hour per IP address, and 10 per hour for any one target.
- Domains you have verified (DNS or file) get a higher allowance.
- Signed-in accounts get their plan's daily allowance. To use it from the API, send your session
token:
Authorization: Bearer <access token>. Personal API keys are planned. - Each scan stops after about 20 seconds.
- Private, internal and reserved addresses (e.g.
localhost,10.0.0.0/8, cloud metadata) are refused.
Errors
Errors return a JSON body like {"error": "rate_limited", "message": "…"}.
| HTTP | error | Meaning |
|---|---|---|
| 400 | invalid_email, consent_required, invalid_tier, invalid_target | Fix the request |
| 403 | verification_required | Full scan of an unverified domain. The response includes a verify object with your token. |
| 422 | blocked_target, dns_failed | Target can't be scanned or doesn't resolve |
| 429 | rate_limited | Wait and try again later |
| 503 / 504 | unavailable, timeout | Temporary problem; retry later |
Need higher limits, scheduled scans or API keys for your team? Get in touch. These are planned for the paid service.
6. Rules & privacy
- Only scan websites you own or have written permission to test. Scanning without permission may be unlawful, including under South Africa's Cybercrimes Act. Abuse is logged and blocked.
- We store your email, the domain, the result and a one-way hash of your IP address for up to a year, in line with POPIA. Ask us to delete them at any time. See the privacy policy.
- Report security issues with this scanner via security.txt.