Documentation

Tools And Guides

Combine focused tools, one-domain tool-suite workflows, and remediation guides for faster, higher-confidence hardening decisions.

Who This Topic Is For

Users who need focused checks and immediate guidance without waiting for broader full-scan cycles.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • A target domain or URL to test.
  • A clear diagnostic question (headers, SSL, DNS, CORS, cookies, or similar category).
  • A decision on whether you need a single-category result, a platform-specific profile, or a one-domain tool-suite run.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Tools answer one question. Scans save a workflow

Public tools are fast and often need no account. Dashboard scans, Watch, and pentest workspaces are the path when you need history, alerts, or a client deliverable.

Guides pair with the same check

After a headers or HSTS tool result, open the matching fix guide, apply the change in staging, then rerun the same tool before calling it closed.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Select the workflow shape that matches your immediate question.

    Use category-specific tool pages for one issue area, use platform-specific profiles for Joomla, Shopify, or WordPress context, and use Run All Tools when you want multiple checks plus generated artifacts in one pass.

  2. Review the paired remediation guide.

    Use the corresponding guide to understand root causes, safer config patterns, and validation steps.

  3. Escalate to broader workflow when needed.

    If one tool reveals wider concerns, move into account-backed scanning for broader coverage, add Website Watch when the origin should stay monitored, or order a Penetration Test / Comprehensive Pentest when you need verified automated active testing with HTML and PDF.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

HSTS gap on a marketing site

Run the HSTS checker, follow the missing-headers guide, apply the header in staging, rerun the tool, then add the production origin to Website Watch so a later header drop emails the team.

The tool proved the fix. Watch watches for regression without another manual HSTS click.

WordPress plugin signal then a Standard scan

The WordPress stack checker flags a plugin version. The team runs Standard from the dashboard for a saved report, then uses Watch for the weekly Standard or Deep cadence on that shop.

The public tool was the signal. The dashboard scan is the record. Watch is the ongoing pulse.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Selected tool scope matches the actual security question.
  • Guide recommendations are validated against your active stack before applying.
  • If a copied URL or generated artifact is shared, the recipient knows what type of output it is.
  • Post-fix check confirms remediation outcome.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Treating one tool as full posture coverage

Focused tools answer focused questions. The one-domain tool suite gives wider public-tool coverage, but broader account-backed scans are still better for recurring validation and saved operational continuity.

Common failure mode

Applying guide snippets without environment checks

Validate config changes in staging first, then rerun the same tool to confirm safe production behavior.

Common failure mode
FAQ

Tools And Guides FAQs

Common questions for this topic.

Public tools are best for category-level diagnostics, platform profiles, and one-domain tool-suite runs. Full scans are still better for broader risk coverage and saved workflow continuity.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.