FAQ

Answers, limits, and how far we can go

Straight answers about the free passive scanner — what it does, what it does not, and how to contact us when you need more than the public baseline.

01

Basics

What is WISP IT?

WISP IT is a free, passive website security scanner. You submit a public domain and get an outside-in snapshot — DNS and reachability, security headers, a short list of well-known open ports, visible tech signals, a risk score, and shareable findings. No account required.

How long does a scan take?

Most scans finish in under a minute. Timing depends on DNS, HTTPS response, and how quickly the target answers the passive checks. The result page updates live while the job runs.

Is WISP IT free?

Yes. The public scanner is free to use. Fair-use rate limits apply so the service stays available for everyone. Need higher volume, custom checks, or a deeper review? Contact us — we can extend coverage.

02

Safety & scope

Is the scan safe for production sites?

Yes for normal public targets. WISP IT only observes signals already visible from the public internet. We do not log in, exploit vulnerabilities, fuzz forms, or run destructive attacks. Private IPs and localhost are blocked.

Do I need permission to scan a site?

Only scan websites you own or are authorized to assess. The checks mirror what any outsider can already see, but you are responsible for how you use the tool and the results.

What does “passive” mean here?

Passive means we read public responses — DNS answers, HTTP(S) headers and HTML hints, and light reachability on a short port list. We do not authenticate, inject payloads, or attempt to breach the application.

03

Limits (and how to go further)

What does this scan not cover?

It is not a full penetration test. It will not find login-only bugs, business-logic flaws, CSRF in authenticated flows, deep API abuse, malware on the host, or a complete port map of every service. It is an outside-in hygiene snapshot — a strong first look, not a complete audit.

Do you scan every port?

No. We probe a short list of well-known ports from the outside — the same kind of view a casual attacker often starts with. That keeps the check fast and non-intrusive. Need a broader or custom port set? Contact us to extend the scan.

Can you extend the scan or help beyond the free tool?

Yes. Contact Back to Earth IT if you want deeper assessment, custom checks, higher limits, recurring monitoring, or help remediating findings. The public FAQ and free scanner are the baseline — we can go further with you.

Why am I rate-limited?

Limits protect the service and scanned targets from abuse. If you need more scans for a team, agency, or client portfolio, contact us and we can discuss expanded access.

04

Results & sharing

How should I read the risk score?

The score summarizes the public signals we collected into one number (0–100 style posture). Lower generally means more concern on the checks we run. Use findings for the actionable detail — the score is a quick overview, not a compliance certificate.

Can I share or download results?

Yes. Each finished scan has a private result link you can share with your team or client. You can also download a PDF when the scan is complete. Treat the link like a report — anyone with it can view that scan.

Are my scan results indexed by Google?

No. Scan result URLs are blocked in robots.txt and served with noindex. They are meant for people you share the link with, not for search engines.

05

Privacy

What data do you store?

We store the target you submit, scan status/score/findings, and limited visitor signals used for rate limiting (such as approximate IP and region when available). Full details, retention, and deletion requests are on the Privacy policy page (/privacy).

Need more

Limits are the free baseline — we can extend

The public tool is intentionally non-intrusive: short port list, no login, no exploit attempts. If you need custom checks, higher volume, recurring monitoring, or help fixing findings, reach out. Back to Earth IT can extend the engagement beyond what this page covers.