Who This Topic Is For
Users who need focused checks and immediate guidance without waiting for broader full-scan cycles.
Combine focused tools, one-domain tool-suite workflows, and remediation guides for faster, higher-confidence hardening decisions.
Users who need focused checks and immediate guidance without waiting for broader full-scan cycles.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
Public tools are fast and often need no account. Dashboard scans, Watch, and pentest workspaces are the path when you need history, alerts, or a client deliverable.
After a headers or HSTS tool result, open the matching fix guide, apply the change in staging, then rerun the same tool before calling it closed.
Follow these steps in order for a reliable and repeatable outcome.
Use category-specific tool pages for one issue area, use platform-specific profiles for Joomla, Shopify, or WordPress context, and use Run All Tools when you want multiple checks plus generated artifacts in one pass.
Use the corresponding guide to understand root causes, safer config patterns, and validation steps.
If one tool reveals wider concerns, move into account-backed scanning for broader coverage, add Website Watch when the origin should stay monitored, or order a Penetration Test / Comprehensive Pentest when you need verified automated active testing with HTML and PDF.
These scenarios show how the workflow looks in practice, including the result you should see.
Run the HSTS checker, follow the missing-headers guide, apply the header in staging, rerun the tool, then add the production origin to Website Watch so a later header drop emails the team.
The WordPress stack checker flags a plugin version. The team runs Standard from the dashboard for a saved report, then uses Watch for the weekly Standard or Deep cadence on that shop.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
Focused tools answer focused questions. The one-domain tool suite gives wider public-tool coverage, but broader account-backed scans are still better for recurring validation and saved operational continuity.
Validate config changes in staging first, then rerun the same tool to confirm safe production behavior.
Use these links to continue your workflow without losing context.
Open Free Security Tools to continue this workflow.
Open Security Guides Hub to continue this workflow.
Open Scans And Depths to continue this workflow.
Open Help: Tools Troubleshooting to continue this workflow.
Open Website Watch to continue this workflow.
Common questions for this topic.
Public tools are best for category-level diagnostics, platform profiles, and one-domain tool-suite runs. Full scans are still better for broader risk coverage and saved workflow continuity.
Continue to the best next page based on where you are in your workflow.