HELP
XyaVora-Scan is a no-account public scanner for quick website security posture checks. Results are evidence-based, progressively rendered, and stored locally only for recent guest scans.
Scan-first workflow
Enter a domain, watch live modules complete, then use the report. Accounts are not part of this phase.
No Account
Scan without registration or user profiles.
Live Results
Cards render as each module finishes.
Local Recent
Guest history stays in browser storage.
HOW SCANS WORK
Enter a public domain
No account, token, or project setup is required. The scanner normalizes the target and blocks private or local network addresses.
Watch live module progress
The report page opens immediately. Cards turn from pending to live results as each analyzer completes.
Review and export
The completed report includes findings, evidence, score details, raw data, and external research links for follow-up validation.
MODULE REFERENCE
Final status, redirects, content type, compression, cache headers, CDN hints, and final host behavior.
A, AAAA, MX, NS, TXT, SPF, and DMARC checks with email security evidence.
HTTPS availability, issuer, validity window, SAN domains, protocol, cipher, and trust evidence.
HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy posture.
Registrar, registration dates, expiry, nameservers, and DNSSEC data where public records are available.
Header, HTML, script, and asset fingerprints for frameworks, CDN, CMS, analytics, hosting, and related tooling.
robots.txt, sitemap files, allowed/disallowed paths, crawl-delay, and discovery evidence.
Optional desktop and mobile capture. It can finish after the core report because screenshots are slower and site-dependent.
FAQ
> Do I need an account?
No. XyaVora-Scan is designed as a public quick scanner. Scan a domain, inspect the report, export if needed, and leave.
> Where are guest reports stored?
Recent guest reports are stored in your browser localStorage as a convenience. They are not a real user account and can disappear if browser storage is cleared.
> Why do results appear gradually?
Analyzers run independently. Fast modules like HTTP or DNS can render first, while slower modules such as WHOIS or screenshots continue in the background.
> Why can a result be partial?
Public websites vary. Some block headless browsers, hide WHOIS details, omit records, redirect heavily, or time out. The report marks evidence quality so uncertain data is not presented as verified.
> Does scanning attack the target?
No. The scanner is passive: DNS lookups, standard HTTP/HTTPS requests, public WHOIS data, robots/sitemap fetches, and optional browser screenshot capture.
> Why is screenshot delayed or missing?
Screenshot capture depends on Playwright, site load behavior, bot defenses, and timeout settings. It is intentionally non-blocking so the core report remains usable.