FAQ
Straight answers about the free passive scanner — what it does, what it does not, and how to contact us when you need more than the public baseline.
01
WISP IT is a free, passive website security scanner. You submit a public domain and get an outside-in snapshot — DNS and reachability, security headers, a short list of well-known open ports, visible tech signals, a risk score, and shareable findings. No account required.
Most scans finish in under a minute. Timing depends on DNS, HTTPS response, and how quickly the target answers the passive checks. The result page updates live while the job runs.
Yes. The public scanner is free to use. Fair-use rate limits apply so the service stays available for everyone. Need higher volume, custom checks, or a deeper review? Contact us — we can extend coverage.
02
Yes for normal public targets. WISP IT only observes signals already visible from the public internet. We do not log in, exploit vulnerabilities, fuzz forms, or run destructive attacks. Private IPs and localhost are blocked.
Only scan websites you own or are authorized to assess. The checks mirror what any outsider can already see, but you are responsible for how you use the tool and the results.
Passive means we read public responses — DNS answers, HTTP(S) headers and HTML hints, and light reachability on a short port list. We do not authenticate, inject payloads, or attempt to breach the application.
03
It is not a full penetration test. It will not find login-only bugs, business-logic flaws, CSRF in authenticated flows, deep API abuse, malware on the host, or a complete port map of every service. It is an outside-in hygiene snapshot — a strong first look, not a complete audit.
No. We probe a short list of well-known ports from the outside — the same kind of view a casual attacker often starts with. That keeps the check fast and non-intrusive. Need a broader or custom port set? Contact us to extend the scan.
Yes. Contact Back to Earth IT if you want deeper assessment, custom checks, higher limits, recurring monitoring, or help remediating findings. The public FAQ and free scanner are the baseline — we can go further with you.
Limits protect the service and scanned targets from abuse. If you need more scans for a team, agency, or client portfolio, contact us and we can discuss expanded access.
04
The score summarizes the public signals we collected into one number (0–100 style posture). Lower generally means more concern on the checks we run. Use findings for the actionable detail — the score is a quick overview, not a compliance certificate.
No. Scan result URLs are blocked in robots.txt and served with noindex. They are meant for people you share the link with, not for search engines.
05
We store the target you submit, scan status/score/findings, and limited visitor signals used for rate limiting (such as approximate IP and region when available). Full details, retention, and deletion requests are on the Privacy policy page (/privacy).
Need more
The public tool is intentionally non-intrusive: short port list, no login, no exploit attempts. If you need custom checks, higher volume, recurring monitoring, or help fixing findings, reach out. Back to Earth IT can extend the engagement beyond what this page covers.