The crawl

LimitValue
PagesThe HTTPS homepage, the plain-HTTP homepage, and up to 10 links on the same host (login, sign-up, contact, checkout and account pages first)
Size500 KB per page
Time10 seconds per request, 40 seconds for the whole module
RedirectsFollowed only when they stay on the same host

Requests are ordinary GETs. The crawl never leaves the verified host, never submits a form and never executes the page's JavaScript: it reads markup and response headers.

Checks

What counts as a personal-data form

A form with fields whose type, name, label or autocomplete hint indicates personal data: email, phone, postal address, date of birth, national identifiers and payment card fields. A password field makes it a login form. web.form-posts-http applies only to forms on HTTPS pages that submit to an http:// address.

Mixed content severity

web.mixed-content is medium when active content (scripts, stylesheets, iframes, objects) loads over HTTP, and low when only images or media do.

Tracking cookies before consent

The finding is raised only when a cookie from a list of well-known analytics and advertising tags arrives in the homepage's own Set-Cookie response. Nothing has been clicked at that point, so the cookie was set before consent, which GDPR and the ePrivacy Directive generally do not allow for non-essential cookies. The finding also says whether a known consent manager was detected on the page. Cookies set later by JavaScript are not seen, because the crawl does not run scripts.

Third-party script inventory

Every third-party script host referenced by your pages is recorded with the scan, which gives you a supply-chain inventory (analytics, chat widgets, tag managers, payment scripts). PCI DSS 4.0 requirement 6.4.3 asks for exactly this inventory on payment pages.