Crawler Policy

Transparency about how ThreatSpot scans websites.

What we do
We perform non-invasive checks like security header inspection, HTTPS configuration review, and public WordPress configuration analysis. We do not brute force logins, submit forms, or attempt exploitation.
User-Agent
You may see scan traffic with one of these identifiers:
ThreatSpotScanner/
Opt-out
If you believe your site is being scanned without authorization, you can request an opt-out.
Domain verification
If you own a domain and your WAF blocks scans, you can verify ownership inside the product to reduce false "Blocked" / "Inconclusive" results.