Who This Topic Is For
Users who already added or tried to add a watched site and need the next operational step or a fix for missing alerts.
Troubleshoot Watch billing, missing alerts, mutes, quiet hours, pause versus cancel, and how Watch differs from Scheduled Scans.
Users who already added or tried to add a watched site and need the next operational step or a fix for missing alerts.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
If the first runs only record what was already there, Watch stays quiet. Alerts start when something new appears, the score drops, or a cert window is hit.
Daily pulse covers headers, certificate days, mixed content, HTTP to HTTPS, and common exposed paths. Weekly Standard or Deep is the matching dashboard pack, locked for that seat. Pulse will not look like a ZAP-backed full scan.
Run pulse now at most once per 15 minutes. Run weekly Standard now or Run weekly Deep now at most once per 6 hours. Scheduled included runs still follow the daily and weekly cadence.
Follow these steps in order for a reliable and repeatable outcome.
Open /watch and click the site.
Status should be active. pending_payment means checkout is not finished.
paused means you stopped runs on purpose. past_due means billing needs the Manage billing portal.
If last pulse is empty, the runner has not completed a pulse yet. If last weekly scan is empty, the weekly Standard or Deep scan has not landed.
Certificate days and last window explain whether a cert alert should already have been sent.
Confirm New findings, Score drop, minimum severity, quiet hours, timezone, extra recipients, and Weekly digest. A High minimum severity will skip a Low header finding.
Quiet hours delay rather than drop the event.
If the finding is listed and you previously clicked Mute, alerts for that fingerprint will not repeat. Click Unmute on the open-issue row or in Muted issues to restore alerts for that fingerprint only.
Custom cadence and Comprehensive still live under Scheduled Scans and the dashboard.
Watch included runs do not deduct credits. If a credit Comprehensive did not run, that is not a Watch defect.
If weekly Deep did not run, confirm the seat is Deep, not Standard.
These scenarios show how the workflow looks in practice, including the result you should see.
Quiet hours are 22:00 to 07:00 America/New_York. A pulse at 01:10 finds a new exposed path. Mail does not arrive at 01:10. It arrives after 07:00.
Watch website returns Watch billing is not configured instead of a Stripe URL. Price IDs are not live for this environment. The site is not watching yet and no seat was added.
The account credit balance is 0. The watch stays active. Next pulse and weekly Standard or Deep still run. A teammate then starts Comprehensive from the dashboard and is blocked until they buy credits.
Use this long-form guidance to execute the workflow consistently across planning, implementation, and validation.
Website Watch is a per-site subscription that answers a narrow question: did this HTTPS origin change in a way you asked to hear about. It is not a pentest. Daily pulse is the same on every seat. Pick Standard or Deep for the weekly scan when you add the site; that depth is locked for the seat. Quick and Comprehensive are not Watch tiers. If a teammate expected Comprehensive, add-ons, or a custom weekday, they are describing Scheduled Scans or a dashboard credit scan. Keep those products in the same account if you need them. Watch still earns its seat when credits are at zero, which is intentional so monitoring does not silently stop during a credit dip. When a ticket says Watch did not scan Comprehensive, the correct reply is to run Comprehensive from the dashboard. When it says Watch did not scan Deep, check whether the seat is Standard or Deep before sending them to a credit scan.
The first successful pulse and weekly Standard or Deep scan establish what already existed. Vulnify does not email every historical finding on day one. After that baseline, alerts fire for new or worsened findings, resolved findings if that setting is on, score drop beyond the threshold, and certificate windows at 30, 14, 7, and expired. The cert window uses the tightest match, so 12 days remaining is a 14-day window rather than 30. If nothing new appeared, no mail is the correct outcome. Before escalating missing email, confirm the watch is active, quiet hours are not covering now, the finding is not muted, and minimum severity is not set above the issue you expected.
Occupied seats include pending_payment, active, paused, and past_due. Pause is a freeze: pulses stop, the site still counts against quantity, and Resume continues from the last baseline. Cancel is an end-of-term drop: the watch stops and quantity decreases at period end without a mid-cycle credit. Agencies should pause during a client freeze and cancel only when the site should leave billing. Adding a sixth client when five seats of that depth are occupied opens Stripe Checkout. Unused paid seats attach without a new checkout only when the new origin uses the same depth. A Standard spare will not cover a Deep origin. If checkout says Watch billing is not configured, payment prices are not live yet and the add cannot succeed until support or an admin finishes Stripe Price setup.
Mute is for accepted risk, staging exceptions, and findings you already track elsewhere. A muted fingerprint remains visible as an open issue with a Muted pill, and it also appears under Muted issues. It drops out of new-finding mail until you click Unmute. Quiet hours delay alerts until the window ends in the watch timezone, which is why a 02:00 pulse may arrive at 07:00. Weekly digest, when enabled, sends Monday at 09:00 in that timezone so operators can review even if they muted noisy items. Extra recipients are capped at five. If Slack or Jira is connected, Watch can also emit a watch.alert event for the same change. Do not disable New findings globally to silence one issue; mute that fingerprint instead.
A useful Watch support request includes the watch name, HTTPS URL, status pill, last pulse time, last weekly scan time, locked depth (Standard or Deep), certificate days, whether quiet hours are set, and whether the missing item is already listed under Open issues as muted. Include whether the user expected a pulse, a weekly Standard, a weekly Deep, or a credit Comprehensive scan. That split prevents a long investigation into the wrong product. Manual Run pulse now is limited to once per 15 minutes and Run weekly Standard now or Run weekly Deep now once per 6 hours, so a second click in the same window is not a failure of the runner.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
The baseline is quiet on purpose. Wait for a later pulse or weekly Standard or Deep scan, or click Run pulse now after the 15-minute limit. Confirm the watch is active and not paused.
Use an HTTPS origin. Watch is not a scanner for plain HTTP sites.
That is correct. Pause occupies the seat. Cancel if the site should leave quantity at period end.
Expected. Pulse is a lightweight daily check. Weekly Standard or Deep is the matching dashboard pack and appears in scan history when a scan_id is present.
Honor the 15-minute pulse and 6-hour full limits. The included daily and weekly schedule is separate from those manual buttons.
Open the watch and click Unmute on that open-issue row, or under Muted issues. You do not need support to clear a mute.
Use these links to continue your workflow without losing context.
Open Documentation: Website Watch to continue this workflow.
Open Website Watch product page to continue this workflow.
Open Help: Billing And Credits to continue this workflow.
Open Documentation: Automation And Integrations to continue this workflow.
Open Contact Support to continue this workflow.
Common questions for this topic.
The first successful runs set a baseline so Watch does not spam existing findings. Alerts start when something new appears, the score drops, or a certificate window is reached.
Continue to the best next page based on where you are in your workflow.