Run your first scan
1 min read
The three steps
- 1Add your app
From the dashboard, paste your app's URL and check the box confirming you're authorized to scan it. A deliberate act, never pre-checked. No install, no prior setup for a classic scan.
- 2Run the classic (passive) scan
Click "Run scan". It's free, read-only, and takes about 2 minutes. No login required.
- 3Read the result
The dashboard shows a score out of 100, the list of findings ranked by severity (critical/high/medium/low/info), and for each one a fix ready to apply.
What actually runs during those ~2 minutes
The scan isn't a black box that "thinks": it's a single flow that runs the base checks first (headers, TLS, exposed secrets, dependencies), then detects your app's stack and adds the relevant modules (for example the Supabase checks, if a Supabase URL/key is detected in the bundle shipped to the browser). A progress bar and the step list update live while it runs: not a generic animation, the real count of checks run out of the total.
What severity alone doesn't tell you
A classic scan structurally cannot see some findings (e.g. per-user BOLA/IDOR): they need a logged-in test account, i.e. active mode. A high passive score doesn't guarantee those don't exist, only that nothing visible while logged out was found. See "The security score and verdicts".