Run your first scan

1 min read

The three steps

  1. 1
    Add your app

    From the dashboard, paste your app's URL and check the box confirming you're authorized to scan it. A deliberate act, never pre-checked. No install, no prior setup for a classic scan.

  2. 2
    Run the classic (passive) scan

    Click "Run scan". It's free, read-only, and takes about 2 minutes. No login required.

  3. 3
    Read the result

    The dashboard shows a score out of 100, the list of findings ranked by severity (critical/high/medium/low/info), and for each one a fix ready to apply.

What actually runs during those ~2 minutes

The scan isn't a black box that "thinks": it's a single flow that runs the base checks first (headers, TLS, exposed secrets, dependencies), then detects your app's stack and adds the relevant modules (for example the Supabase checks, if a Supabase URL/key is detected in the bundle shipped to the browser). A progress bar and the step list update live while it runs: not a generic animation, the real count of checks run out of the total.

What severity alone doesn't tell you

A classic scan structurally cannot see some findings (e.g. per-user BOLA/IDOR): they need a logged-in test account, i.e. active mode. A high passive score doesn't guarantee those don't exist, only that nothing visible while logged out was found. See "The security score and verdicts".

Was this article helpful?