What the target needs
- It must be reachable from the public internet, on port 80, 443, or a port from 8000 to 8999.
- If a firewall protects it, allow the IP address that the scan form shows.
- The scan must run on pay as you go, or on your own model with an OpenRouter key.
Test the findings of one scan
In the live validation step of the scan form:- Enter the target URL, for example
https://staging.example.com. - Optionally, add testing instructions, such as the test account to sign in with, the pages to test, and the actions to avoid. Put the login here, not in the URL.
- Confirm that you are authorized to test the target.
Save a target for a repository
An Owner or Admin can save a target for a connected repository. Every scan of that repository then tests against it, including pull request scans.- Select GitHub in the sidebar.
- On the repository’s row, select Live validation.
- Enter the target URL and the testing instructions, confirm your authorization, and select Save.
What gets tested
After the review step, the platform tests every finding that is not a duplicate and not out of scope. Each test has a time limit of 10 minutes. A finding that describes a missing control, such as a missing security header, gets nothing to reproduce without a test.Results
Each finding on the scan page shows a live badge with its result. On the finding page, the Validation tab shows the test and the Evidence tab shows its proof. See Findings. If the tests did not run, the scan page says why.

