The crawl
| Limit | Value |
|---|---|
| Pages | The HTTPS homepage, the plain-HTTP homepage, and up to 10 links on the same host (login, sign-up, contact, checkout and account pages first) |
| Size | 500 KB per page |
| Time | 10 seconds per request, 40 seconds for the whole module |
| Redirects | Followed only when they stay on the same host |
Requests are ordinary GETs. The crawl never leaves the verified host, never submits a form and never executes the page's JavaScript: it reads markup and response headers.
Checks
web.login-form-httphigh Login form without encryptionweb.pii-form-httphigh Personal-data form without encryptionweb.form-posts-httphigh Form submits to an unencrypted addressweb.mixed-contentvaries Mixed contentweb.third-party-script-no-srilow Third-party script without integrity checkweb.tracking-cookie-before-consentlow Tracking cookie set before consent
What counts as a personal-data form
A form with fields whose type, name, label or autocomplete hint indicates personal data: email,
phone, postal address, date of birth, national identifiers and payment card fields. A password
field makes it a login form. web.form-posts-http applies only to forms on HTTPS pages
that submit to an http:// address.
Mixed content severity
web.mixed-content is medium when active content (scripts, stylesheets,
iframes, objects) loads over HTTP, and low when only images or media do.
Tracking cookies before consent
The finding is raised only when a cookie from a list of well-known analytics and advertising
tags arrives in the homepage's own Set-Cookie response. Nothing has been clicked at that
point, so the cookie was set before consent, which GDPR and the ePrivacy Directive generally do not
allow for non-essential cookies. The finding also says whether a known consent manager was detected
on the page. Cookies set later by JavaScript are not seen, because the crawl does not run scripts.
Third-party script inventory
Every third-party script host referenced by your pages is recorded with the scan, which gives you a supply-chain inventory (analytics, chat widgets, tag managers, payment scripts). PCI DSS 4.0 requirement 6.4.3 asks for exactly this inventory on payment pages.