Kategori
Category
Website security
-
Rate Limit Signals
Rate Limit Signals — Looks for RateLimit-*, Retry-After, and 429 signals (≤2 extra requests). Business-friendly documentation for this…
-
GraphQL Introspection
GraphQL Introspection — Probes a discovered GraphQL endpoint once for public introspection. Business-friendly documentation for this Guardbee scan…
-
JS Supply Chain
JS Supply Chain — Maps frontend library versions from script URLs to an offline advisory list. Business-friendly documentation…
-
Deep TLS Analysis
Deep TLS Analysis — Inspects negotiated TLS protocol, cipher suite, and certificate chain signals. Business-friendly documentation for this…
-
Authenticated Crawl
Authenticated Crawl — Uses Capture traffic login results to inventory auth-gated same-origin API traffic. Business-friendly documentation for this…
-
CORS Policy
CORS Policy — Analyzes Access-Control-* headers with at most one harmless Origin reflection probe. Business-friendly documentation for this…
-
Third-Party Scripts
Third-Party Scripts — Inventories external script hosts and flags missing SRI / crossorigin. Business-friendly documentation for this Guardbee…
-
Form Security
Form Security — Inspects HTML forms for CSRF tokens, insecure autocomplete, and password fields over HTTP. Business-friendly documentation…
-
Open Redirect
Open Redirect — Unvalidated redirect / return URL parameters (CWE-601). Business-friendly documentation for this Guardbee scan module.
-
Subdomain Takeover
Subdomain Takeover — Checks common subdomain labels for dangling CNAMEs to claimable hosting. Business-friendly documentation for this Guardbee…
-
DNS & Email Security
DNS & Email Security — Validates SPF, DKIM, DMARC, and DNSSEC DS signals. Business-friendly documentation for this Guardbee…
-
Sensitive Paths
Sensitive Paths — Probes .env, .git, backups, and admin/debug paths for public exposure. Business-friendly documentation for this Guardbee…