Skip to main content
A browser runs the attack of each finding against your application and records the requests, screenshots, and a video as proof. Live validation is optional.
Live tests send real attack requests, and a test can change or delete data. Test only applications that you own or are authorized to test. Use a test or staging environment, not production.

What the target needs

  • It must be reachable from the public internet, on port 80, 443, or a port from 8000 to 8999.
  • If a firewall protects it, allow the IP address that the scan form shows.
  • The scan must run on pay as you go, or on your own model with an OpenRouter key.

Test the findings of one scan

In the live validation step of the scan form:
  1. Enter the target URL, for example https://staging.example.com.
  2. Optionally, add testing instructions, such as the test account to sign in with, the pages to test, and the actions to avoid. Put the login here, not in the URL.
  3. Confirm that you are authorized to test the target.
To skip live tests, leave the fields empty, unless the repository has a saved target.

Save a target for a repository

An Owner or Admin can save a target for a connected repository. Every scan of that repository then tests against it, including pull request scans.
  1. Select GitHub in the sidebar.
  2. On the repository’s row, select Live validation.
  3. Enter the target URL and the testing instructions, confirm your authorization, and select Save.
The scan form fills in the saved target, and you can change it for one scan. To stop live tests for the repository, select Remove in the same dialog. A pull request scan tests the code that is deployed on the target, which may not include the changes in the pull request. Pull requests from forks never run live tests.
Every member of your organization, viewers included, can read saved testing instructions and the evidence of each test. The evidence includes the session of the test login. Use a test account with no access to real data.

What gets tested

After the review step, the platform tests every finding that is not a duplicate and not out of scope. Each test has a time limit of 10 minutes. A finding that describes a missing control, such as a missing security header, gets nothing to reproduce without a test.

Results

Each finding on the scan page shows a live badge with its result. On the finding page, the Validation tab shows the test and the Evidence tab shows its proof. See Findings. If the tests did not run, the scan page says why.